search menu icon-carat-right cmu-wordmark

CERT Coordination Center

HTTP content scanning systems full-width/half-width Unicode encoding bypass

Vulnerability Note VU#739224

Original Release Date: 2007-05-14 | Last Revised: 2009-04-22

Overview

Various HTTP content scanning systems fail to properly scan full-width/half-width Unicode encoded traffic. This may allow malicious HTTP traffic to bypass content scanning systems.

Description

Full-width and half-width encoding is a technique for encoding Unicode characters. Various HTTP content scanning systems fail to properly scan full-width/half-width Unicode encoded HTTP traffic. By sending specially-crafted HTTP traffic to a vulnerable content scanning system, an attacker may be able to bypass that content scanning system.

Impact

A remote, unauthenticated attacker may be able to bypass HTTP content scanning systems.

Solution

Check with your vendor

Refer to the Systems Affected section of this document for information about specific vendors regarding this issue.

Vendor Information

739224
 

View all 95 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This issue was reported by Fatih Ozavci and Caglar Cakici of Gamasec Security.

This document was written by Jeff Gennari.

Other Information

CVE IDs: None
Severity Metric: 1.76
Date Public: 2007-05-14
Date First Published: 2007-05-14
Date Last Updated: 2009-04-22 18:54 UTC
Document Revision: 24

Sponsored by CISA.