Proxytunnel Remote Format String Vulnerability
BID:11592
Info
Proxytunnel Remote Format String Vulnerability
| Bugtraq ID: | 11592 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2004 12:00AM |
| Updated: | Nov 03 2004 12:00AM |
| Credit: | Discovery is credited to Florian Schilhabel of the Gentoo Linux Security Audit project. |
| Vulnerable: |
proxytunnel proxytunnel 1.2.2 proxytunnel proxytunnel 1.2 .0 proxytunnel proxytunnel 1.1.3 proxytunnel proxytunnel 1.0.6 |
| Not Vulnerable: |
proxytunnel proxytunnel 1.2.3 |
Discussion
Proxytunnel Remote Format String Vulnerability
Proxytunnel is prone to a remotely exploitable format string vulnerability. This vulnerability is exposed when the proxy server handles malicious input from another remote server. This issue occurs when the software is run in daemon mode.
Successful exploitation of this vulnerability may allow for execution of arbitrary code in the context of the proxy server.
Proxytunnel is prone to a remotely exploitable format string vulnerability. This vulnerability is exposed when the proxy server handles malicious input from another remote server. This issue occurs when the software is run in daemon mode.
Successful exploitation of this vulnerability may allow for execution of arbitrary code in the context of the proxy server.
Exploit / POC
Proxytunnel Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Proxytunnel Remote Format String Vulnerability
Solution:
Gentoo has released an advisory that provides updates for this issue. Updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=net-misc/proxytunnel-1.2.3"
This issue is addressed in proxytunnel 1.2.3.
proxytunnel proxytunnel 1.0.6
proxytunnel proxytunnel 1.1.3
proxytunnel proxytunnel 1.2 .0
proxytunnel proxytunnel 1.2.2
Solution:
Gentoo has released an advisory that provides updates for this issue. Updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=net-misc/proxytunnel-1.2.3"
This issue is addressed in proxytunnel 1.2.3.
proxytunnel proxytunnel 1.0.6
-
proxytunnel proxytunnel 1.2.3
http://sourceforge.net/project/showfiles.php?group_id=39840
proxytunnel proxytunnel 1.1.3
-
proxytunnel proxytunnel 1.2.3
http://sourceforge.net/project/showfiles.php?group_id=39840
proxytunnel proxytunnel 1.2 .0
-
proxytunnel proxytunnel 1.2.3
http://sourceforge.net/project/showfiles.php?group_id=39840
proxytunnel proxytunnel 1.2.2
-
proxytunnel proxytunnel 1.2.3
http://sourceforge.net/project/showfiles.php?group_id=39840