List of changes for SG3.2.4.8

Report created December 15, 2004
IssueService RequestDescription
42629NONEUnder rare circumstances it is possible for the ProxySG to restart with signature (Hdw: 0x2 Sfw: 0x19 Pgflt: 0x0 - Find_src_IP_bypass_addr()) if dynamic bypass is enabled and rapid insertions of entries is taking place.
434021-7462430Browser pop-up blockers were preventing patience pages from lauching, resulting in object download failures.
440021-8022481The rewriting of absolute URLs does not work inside of an embedded javascript.
442551-9207184Accesslog does not log "QUIT" for cs-method field on closing connection with FTP server.
445181-7026671Provide a global configuration option to not buffer HTTP responses that do not adhere to HTTP length specifications.
446171-7163451, 1-8553634Resolve a pagefault restart in HTTP SW in "http.dll" at .text+0x5FDC1.
447301-7076901, 1-7346480, 1-7617431, 1-7857463, 1-8082104, 1-8387451, 1-8476917, 1-9450431, 1-9580451Prevent a possible page fault in MMS HTTP ClntW in "cfs.dll" at .text+0xA39.
447481-7168863It was possible for the DNS proxy to leak memory causing an out of memory restart
447751-6910125, 1-8338014Meta tag parsing would occasionally fail for HTML pages that were larger than 1000 bytes.
44840NONEPrevent a page fault at 0x49AAB00 "ce_admin.dll" at .text+0x32D1 when uploading an access log via the service info feature.
449911-7494643The ProxySG was not correctly rewriting embedded relative urls that begin with a question mark.
449921-7210754, 1-7570599It was possible for policy decisions on ftp/telnet transactions to be overridden by policy that requires a server response.
450171-7635100, 1-8865204Prevent a page fault at 0x0 in "HTTP RW" in "http.dll" when parsing an HTTP 407 response.
450631-7547995When using popup blocking, some pages did not render properly in Internet Explorer.
450971-7340601Force_cache(yes) does not work for urls that contain query strings or cookies.
45127NONEPrevent a page fault at 0x8 in "tcpip.dll" at .text+0x9F6A when accessing the dynamic bypass list.
45153NONEPrevent a page fault in "HTTP CW" in "http.dll" at .text+0x5B840.
45161NONEThe ProxySG did not properly escape special characters when performing LDAP searches.
451711-7507676Upon expiration of the ProxySG and Siteminder authentication cookies, subsequent user authentication attempts could fail.
452091-7691193, 1-8689477Director policy pushes would fail when using SSH v2.
452441-7734026It was possible for LDAP worker to page fault in cfssl.dll at .text+0x61D2B if the LDAP directory's response resulted in multiple referrals.
452481-7781660CLI users could authenticate without sending a password if the the LDAP directory allowed anonymous binds.
454721-7163451Prevent restart SW: 0x30 in "Kernel.dll" at .text+0x827C when bandwidth-gain mode and icap are enabled
455231-8149149Local bypass list entries for hosts on the local subnet were timing out.
455421-8187556, 1-8588671It was possible for the realm passwd for websense reporter username to be null, resulting in a page fault with process "ALOGAdmin:websense-main" in "authenticator.dll" at .text+0x289EE
455621-8149384It was possible for forms based auth to fail with HTP_INVALID_AUTH_FORM if password contained a '?'
455661-8178306TFTP uploads would fail with some TFTP servers due to the SG adding a leading slash to the filename.
455811-8782780The ProxySG will no longer limit NTLM proxy authentication to a finite list of User-Agents.
457181-8022488, 1-8371554A fragmented POST request for forms based auth submission could result in INVALID_AUTH_FORM
457491-8000551Proxy credentials can be leaked upstream when the authenticate(no) property is used.
458381-8231485FTP proxy clients could receive chunk encoded data when using ICAP.
458781-8450815Prevent an MMS stream fetch failure when the media server's response contained more than 32 packet fragments
459201-8387763The Radius splash generator secret could not be entered via the CLI.
460831-8179771Resolve a Page Fault in "IM_Admin" in "im.dll" at .text+0x4451.
461841-7035345HTTP downloads would continue after client abandonment when bandwidth gain mode is enabled if the patience page was being used.
462631-8626589, 1-8689805, 1-9357095, 1-9498407Resolve a Page Fault in MSN IM Worker in "im.dll" at .text+0x2BDB6.
463701-8497926The access log size reported for service-info was incorrect if the logs were very large.
464451-8688461Prevent RTPS forwarding from failing if a DNS hostname resolution of the target URL did not succed.
46451NONEPrevent a case where categorized HTTPS sites could bypass policy.
465061-8802916Websense Reporter was receiving the NTLM prefix "WinNT" formatted incorrectly.
465221-8744033Support Netware style directory listings for web FTP.
465321-8635696It was possible for VPM to generate url.host= CPL for destination host/port instead of url.domain=
466371-8535512CPU usage could spike in the event of an ICAP server failure.
467231-8537791GigE card does not link up after unplugging the network cable
467261-8743821Prevent ProxySG from displaying SEVERE_ERROR on syslog when logging in via SSH
467331-8864778Prevent page fault in process "HTTP SW in "http.dll" at .text+0x52468
467411-8565556Prevent x-bluecoat-websense-user from resulting in a null value when a LDAP realm in a sequence realm is used to authenticate Proxy users.
467841-8656209When a Socks UDP Associate was performed to the ProxySG virtual ip address, the Proxy SG would respond with the IP address of the network interface instead of the vip.
469101-7912959Add support to allow global configuration of TTL for DNS negative caching.
469671-9202976Forwarding rule is not converted properly when invoking upgrade from SG 2.1.10 to SG 3.2.3
470121-9055096RTSP proxy selects RDT as transport protocol when Helix server sends live broadcast using RTP.
470801-8248481, 1-8471981, 1-8898959, 1-9031595After an upgrade to SG3.2.x, prevent ProxySG from sending websense log v1 records while negotiating log v3.