Delegate POP Proxy USER Buffer Overflow Vulnerability
BID:4055
Info
Delegate POP Proxy USER Buffer Overflow Vulnerability
| Bugtraq ID: | 4055 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 07 2002 12:00AM |
| Updated: | Feb 07 2002 12:00AM |
| Credit: | Discovered by Tom Parker (Global InterSec LLC). |
| Vulnerable: |
DeleGate DeleGate 7.8.1 DeleGate DeleGate 7.8 .0 DeleGate DeleGate 7.7.1 DeleGate DeleGate 7.7 .0 |
| Not Vulnerable: | |
Discussion
Delegate POP Proxy USER Buffer Overflow Vulnerability
DeleGate is an open source proxy server developed by Yutaka Sato. DeleGate allows for proxy of several application protocols, including POP.
Delegate is reportedly vulnerable to a stack-based buffer overflow that may allow for the execution of arbitrary code. The condition exists if the argument to the 'USER' command is of excessive length.
Additionally, several other buffer overflow conditions in DeleGate reportedly exist.
DeleGate is an open source proxy server developed by Yutaka Sato. DeleGate allows for proxy of several application protocols, including POP.
Delegate is reportedly vulnerable to a stack-based buffer overflow that may allow for the execution of arbitrary code. The condition exists if the argument to the 'USER' command is of excessive length.
Additionally, several other buffer overflow conditions in DeleGate reportedly exist.
Exploit / POC
Delegate POP Proxy USER Buffer Overflow Vulnerability
It is believed that an exploit exists.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
It is believed that an exploit exists.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Delegate POP Proxy USER Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.