Check Point Reference: | CPAI-2011-318 |
Date Published: | 28 Jun 2011 |
Severity: | High |
Last Updated: | Tuesday 16 September, 2014 |
Source: | |
Industry Reference: | CVE-2009-4086 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | |
Vulnerability Description | This is a CRLF injection vulnerability in Xerver HTTP Server. Remote attackers could use this vulnerability to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain byte sequences at the end of a URL |
This protection will detect and block CLRF encoded characters in HTTP request
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: Web Server Enforcement Violation.
Attack Information: Xerver HTTP CRLF injection response splitting