FreeBSD : ziproxy -- multiple vulnerability (872ae5be-29c0-11de-bdeb-0030843d3802)
Medium Nessus Plugin ID 36168
SynopsisThe remote FreeBSD host is missing a security-related update.
DescriptionZiproxy Developers reports :
Multiple HTTP proxy implementations are prone to an information-disclosure vulnerability related to the interpretation of the 'Host' HTTP header. Specifically, this issue occurs when the proxy makes a forwarding decision based on the 'Host' HTTP header instead of the destination IP address.
Attackers may exploit this issue to obtain sensitive information such as internal intranet webpages. Additional attacks may also be possible.
SolutionUpdate the affected package.