-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2015.0121
                  ProxySG and ASG Coaching Page Redirect
                             23 December 2015

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Blue Coat ProxySG
                      Blue Coat ASG
Operating System:     Network Appliance
Impact/Access:        Provide Misleading Information -- Remote with User Interaction
Resolution:           Patch/Upgrade
Member content until: Friday, January 22 2016

OVERVIEW

        A low severity vulnerability has been identified in Blue Coat ProxySG 
        6.5 prior to 6.5.8.8, ProxySG 6.6, and ASG 6.6.


IMPACT

        The vendor has provided the following information:
        
        "The URL displayed by ProxySG and ASG in a coaching page may differ
        from the actual URL that the user will be directed to after clicking
        Accept. A user who clicks on a specially crafted URL can be directed
        to an undesired or possibly malicious web site." [1]


MITIGATION

        For ProxySG 6.6 and ASG 6.6 there are no fixes available. The vendor
        has advised the following:
        
        "Review the categories that are blocked and ensure that users are 
        not allowed to access content that is undesired and/or dangerous 
        such as Malware, Phishing, and Botnet." [1]
        
        There is a patch available for Proxy 6.5.8.8. [1]


REFERENCES

        [1] SA107: ProxySG and ASG Coaching Page Redirect
            https://bto.bluecoat.com/security-advisory/sa107

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBVnoLZH6ZAP0PgtI9AQJdHw//UpgZVgkGiX2GaxsL2zQKdxVUy6wYUYc4
08YQYdgNEsixWoDqcRxS8P6JH6Ctk5Vp2r+/JiRICxklyB9OG8L6Cw+04Hsg+ZAG
npfm+CqVa38il7cu+0yla7Lja+YK89wz9JmD4adi+xlnoxDFQX1PSypY3QFp0ze8
mLDT6aCDVqDqQyjMUsOERj91qAynPgwAYF1izGKUM0dVE8BwKd/fI25RNYCkePsI
A1eGhfn+dIfiZQlx+Y+ZmR2olzucByzSIDZa+WzncEHS4+erimP+uFtxGhyOjmUR
a+XDycXd3KktWLWjYZZ8r2e6Qu8seBoX/DZcdFeWjvCXEU762KGQp5yytsUjzZFP
OyhY5281+52tVf/UKmC2z/ymYv/h6BfYjAL6O4P0T9sqVo0LyGxszKsxgrF5gBZc
ZcafIVybFd6RZTEutQEYvcHOtzTb0mB/7Gp45Cg/ESaO70cqHLRj9e/2GMOyAC7+
Lb1TSXHP9jygNyAZ5ONbSxaGwzC/40MKYbqSIoSwVp30M6gMD9cVE6D38/F5pnnb
sE9wSsH9jJpXi14RRQnxeTCbpyBUijD/Ge0y2ks6AEfnDQPmNRBovMOWdQibPA8T
elB+M2KfeCKfhrtJVRa0E8o+Zlm9MYJo2tnsNlWPAzr/kCC0lQ4JpFDn97n++Qdf
pq57eEI+Q7c=
=Gh1n
-----END PGP SIGNATURE-----