SapporoWorks WinProxy Buffer Overflow Vulnerability
BID:1400
Info
SapporoWorks WinProxy Buffer Overflow Vulnerability
| Bugtraq ID: | 1400 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2000-0593 CVE-2000-0592 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jun 27 2000 12:00AM |
| Updated: | Jul 11 2009 02:56AM |
| Credit: | Discovered by UNYUN <[email protected]> and posted to Bugtraq on June 27, 2000 by Nobuo Miwa <[email protected]>. |
| Vulnerable: |
SapporoWorks WinProxy 2.0.1 SapporoWorks WinProxy 2.0 |
| Not Vulnerable: |
SapporoWorks WinProxy 2.0.2 |
Discussion
SapporoWorks WinProxy Buffer Overflow Vulnerability
Multiple unchecked buffers exist in the POP3 and HTTP Proxy components of SapporoWorks WinProxy which could open up the possibilities of denial of service attacks or remote execution of arbitrary code.
Performing a "GET /" on port 8080 will cause WinProxy to stop responding.
The USER, PASS, LIST, RETR, and DELE commands allow for arbitrary code to be executed when strings over 312 bytes are entered. The USER and PASS command are vulnerable to buffer overflow even without authentication procedures.
Multiple unchecked buffers exist in the POP3 and HTTP Proxy components of SapporoWorks WinProxy which could open up the possibilities of denial of service attacks or remote execution of arbitrary code.
Performing a "GET /" on port 8080 will cause WinProxy to stop responding.
The USER, PASS, LIST, RETR, and DELE commands allow for arbitrary code to be executed when strings over 312 bytes are entered. The USER and PASS command are vulnerable to buffer overflow even without authentication procedures.
Solution / Fix
SapporoWorks WinProxy Buffer Overflow Vulnerability
Solution:
SapporoWorks has released version 2.0.2 which eliminates the vulnerability and is available for download at the following location:
http://homepage2.nifty.com/spw/winproxy/download.html
Solution:
SapporoWorks has released version 2.0.2 which eliminates the vulnerability and is available for download at the following location:
http://homepage2.nifty.com/spw/winproxy/download.html
References
SapporoWorks WinProxy Buffer Overflow Vulnerability
References:
References:
- WinProxy Product Homepage (SapporoWorks)