Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT Security Bulletin ASB-2014.0086 A vulnerability has been reported in Barracuda Web Filter v6.0.1 and earlier 24 July 2014 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Barracuda Web Filter Operating System: Network Appliance Impact/Access: Cross-site Scripting -- Existing Account Resolution: Patch/Upgrade Member content until: Saturday, August 23 2014 OVERVIEW A vulnerability has been reported in Barracuda Web Filter v6.0.1 and earlier. [1] IMPACT Barracuda has provided the following details regarding these issues: "The product version listed above is vulnerable to an authenticated persistent XSS attack. Successful exploitation requires an attacker to authenticate with the system and then submit a payload into one of the configuration settings. The attacker must then convince another user\administrator to view\modify the setting in question to trigger the payload of malicious code." [1] MITIGATION The vendor recommends upgrading to the latest version of the affected product. [1] REFERENCES [1] BNSEC-02361: Authenticated persistent XSS in Barracuda Web Filter v6.0.1 https://www.barracuda.com/support/knowledgebase/501600000013m4O AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBU9B3cxLndAQH1ShLAQL2WA/+IYsAThN3inkSHqea4UTPUkjgI+Pjc4+k zcQgwY+8OOFk9ZgSe3xDo/EfWCcWj4xCLYuenJmInn/jyR0ik24ScI5HkOfawi0V 5qj3RqjWBhD78vE2Vmjg0Fnjg745RKmVViaeOLdBzZf9+uww+ED46ao5wIlHYkfd HTbeJqeFydjUMGNlioLfWcWKiP5UH5/uIVDcN6W/bNv3zaTPpfYEjwuq9CXyojaz X6cO+rVo+MTfSHM5sLT4+DkxmlK8JsfB8ZrNbBxEQIHlrfG4kXztUHfkurp3P8Ho IcQIbun2Ro4j6ObTj2oIpx9bz3A7LhQXGhMCbd2XbMXZNVTzD2eHOkC+/8XR0Cys KHZbNDP8dWXEdOG9cGnq5RTqqRALNPXCGtago8e6agbTo+YRFO66LeWihTXEfWtj mSMp3FrHBYzcrHqZlAis0JiYcqJ29l0KXaER3bd6SLR/N0GioQ4NfRJsZ1kncZpV 1ATCQQp1f+i+wcVacCClIT8iyk5asTgUwDG/lXI+DUoM0ABuXkoaEjuxrrNB9FKJ Shda9MvfyWMx/4FgvlowTbI1+oY+MqeDH3WtDLcDlsfeNZRyGBVCAUgCLG8a8J/Z Npdyhbd9ITPLKtBPqEdtVqqSkhmgEe2rVr+T/rqVJyL82RDEGXkj/NIp6yiRbkDU fFkZLhgk+kY= =woDb -----END PGP SIGNATURE-----