<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA's security advisory stance needs fixing. PANOS less that 5.0.9 contains XSRF and I just happened to stumble on this, on an unrelated site in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40777#M29951</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just wanted to update that I got an explanation from PSIRT and even if I dont fully agree with them I do understand their point of view.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In short: an advisory will show up as soon as there is a fix available for all current PANOS versions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Jan 2014 22:35:52 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2014-01-22T22:35:52Z</dc:date>
    <item>
      <title>PA's security advisory stance needs fixing. PANOS less that 5.0.9 contains XSRF and I just happened to stumble on this, on an unrelated site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40772#M29946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just stumbled on this security advisory while I was googling something totally unrelated...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://packetstormsecurity.com/files/124184/panp-xssxsrf.txt"&gt;http://packetstormsecurity.com/files/124184/panp-xssxsrf.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"These issues have been fixed in PANOS 5.0.9, mentioned in the release notes like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;57343—Fixed an issue that caused improper handling of imported certificates that contained HTML."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I think this vulnerability isn't even listed here, on PA's Security Advisories page:&lt;/P&gt;&lt;P&gt;&lt;A href="https://securityadvisories.paloaltonetworks.com/" title="https://securityadvisories.paloaltonetworks.com/"&gt;Palo Alto Networks Product Vulnerability - Security Advisories&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the actual vulnerability:&lt;/P&gt;&lt;P&gt;"&lt;CODE&gt;A couple of bugs exist in Palo Alto Networks PANOS &amp;lt;= 5.0.8 which can be exploited to conduct cross-site scripting attacks.&lt;BR /&gt;&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;Certificate fields are displayed in the firewall web interface without proper sanitization applied to them. This way it is possible to inject html into the web interface.&lt;BR /&gt;&lt;BR /&gt;Various file upload forms used by the firewall do not implement proper CSRF protection. import.certificate.php for example. "&lt;/CODE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Dec 2013 15:04:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40772#M29946</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-12-06T15:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: PA's security advisory stance needs fixing. PANOS less that 5.0.9 contains XSRF and I just happened to stumble on this, on an unrelated site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40773#M29947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;One month later,&lt;/STRONG&gt; still nothing about this on &lt;A href="https://securityadvisories.paloaltonetworks.com/"&gt;https://securityadvisories.paloaltonetworks.com/&lt;/A&gt;.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jan 2014 03:07:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40773#M29947</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-01-06T03:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: PA's security advisory stance needs fixing. PANOS less that 5.0.9 contains XSRF and I just happened to stumble on this, on an unrelated site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40774#M29948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also opened a TAC case for this, answer from there is that the information is not yet published in the security advisories because the fix for PANOS 4.1.x is not available until now.....discussible argumentation...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jan 2014 21:56:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40774#M29948</guid>
      <dc:creator>indup089</dc:creator>
      <dc:date>2014-01-09T21:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: PA's security advisory stance needs fixing. PANOS less that 5.0.9 contains XSRF and I just happened to stumble on this, on an unrelated site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40775#M29949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's not an acceptable answer to me! When I can find the vulnerability on &lt;A href="http://packetstormsecurity.com/files/124184/panp-xssxsrf.txt" title="http://packetstormsecurity.com/files/124184/panp-xssxsrf.txt"&gt;Palo Alto Networks PanOS 5.0.8 XSS / CSRF ≈ Packet Storm&lt;/A&gt; Packet Storm's site, it's out there for the public! At least let customers know there's a vulnerability&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jan 2014 22:05:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40775#M29949</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-01-09T22:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: PA's security advisory stance needs fixing. PANOS less that 5.0.9 contains XSRF and I just happened to stumble on this, on an unrelated site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40776#M29950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tried to file the above as a report towards PSIRT, lets see how long it will take for them to reply...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jan 2014 09:03:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40776#M29950</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2014-01-21T09:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: PA's security advisory stance needs fixing. PANOS less that 5.0.9 contains XSRF and I just happened to stumble on this, on an unrelated site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40777#M29951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just wanted to update that I got an explanation from PSIRT and even if I dont fully agree with them I do understand their point of view.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In short: an advisory will show up as soon as there is a fix available for all current PANOS versions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jan 2014 22:35:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40777#M29951</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2014-01-22T22:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: PA's security advisory stance needs fixing. PANOS less that 5.0.9 contains XSRF and I just happened to stumble on this, on an unrelated site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40778#M29952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for dilligently chasing this down &lt;A href="https://live.paloaltonetworks.com/u1/3245"&gt;mikand&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 00:17:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-s-security-advisory-stance-needs-fixing-panos-less-that-5-0-9/m-p/40778#M29952</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-01-23T00:17:17Z</dc:date>
    </item>
  </channel>
</rss>

