View Issue Details [ Jump to Notes ] | [ Issue History ] [ Print ] |
ID | Project | Category | View Status | Date Submitted | Last Update |
0000625 | ClearOS | app-firewall - Firewall | public | 2012-05-25 10:11 | 2012-06-05 17:46 |
|
Reporter | bchambers | |
Assigned To | dsokoloski | |
Priority | normal | Severity | major | Reproducibility | always |
Status | closed | Resolution | fixed | |
Platform | | OS | | OS Version | |
Product Version | 6.2.0 | |
Target Version | 6.2.0 Updates | Fixed in Version | 6.2.0 Updates | |
|
Summary | 0000625: Validation routine in Firewall class allows invalid entries |
Description |
validate_address function will allow address entered as a hostname with no 'dot' (eg. toronto) as OK. In addition to violating RFC standards, it breaks ClearOS's own API when a hostname is used and other libraries validate the hostname used by the Network_Utils class. |
Steps To Reproduce | In Egress firewall, enter a destination domain rule with a hostname with no dots...eg. toronto |
Additional Information | If you have come up against this bug, remote the offending line by editing the file /etc/clearos/firewall.conf near the bottom of the file. |
Tags | No tags attached. |
|
Attached Files | |
|