SapporoWorks Black JumboDog HTTP Proxy Buffer Overflow Vulnerability
BID:3858
Info
SapporoWorks Black JumboDog HTTP Proxy Buffer Overflow Vulnerability
| Bugtraq ID: | 3858 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Jan 01 2002 12:00AM |
| Updated: | Jan 01 2002 12:00AM |
| Credit: | Disclosed to Bugtraq-JP by Shadow Penguin Security on January 10, 2002. |
| Vulnerable: |
SapporoWorks Black JumboDog 2.6.5 SapporoWorks Black JumboDog 2.6.4 |
| Not Vulnerable: |
SapporoWorks Black JumboDog 2.6.6 |
Discussion
SapporoWorks Black JumboDog HTTP Proxy Buffer Overflow Vulnerability
Black JumboDog 2.6.4 and 2.6.5 HTTP proxy is vulnerable to an exploitable buffer overflow. The buffer overflow can be exploited by sending excessively long "expires", "if-modified-since", and "Last_Modified" strings containing executable code. A client must be able to use the Black JumboDog HTTP proxy function. Black JumboDog also has mail proxy functions and this buffer overflow can be exploited with HTML mail. This is a japanese software product.
Black JumboDog 2.6.4 and 2.6.5 HTTP proxy is vulnerable to an exploitable buffer overflow. The buffer overflow can be exploited by sending excessively long "expires", "if-modified-since", and "Last_Modified" strings containing executable code. A client must be able to use the Black JumboDog HTTP proxy function. Black JumboDog also has mail proxy functions and this buffer overflow can be exploited with HTML mail. This is a japanese software product.
Exploit / POC
SapporoWorks Black JumboDog HTTP Proxy Buffer Overflow Vulnerability
References
SapporoWorks Black JumboDog HTTP Proxy Buffer Overflow Vulnerability
References:
References:
- [SPSadvisory#42]Black JumboDog 2.6.4/2.6.5 Buffer Overflow (SPS
) - BlackJumboDog Homepage (SapporoWorks)
- SPS Advisory #42 - Black JumboDog 2.6.4/2.6.5 Buffer Overflow (Shadow Penguin Security)