AnalogX Proxy Socks4A Buffer Overflow Vulnerability
BID:5138
Info
AnalogX Proxy Socks4A Buffer Overflow Vulnerability
| Bugtraq ID: | 5138 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1001 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Discovery of this issue is credited to "Foundstone Labs" <[email protected]>. |
| Vulnerable: |
AnalogX Proxy 4.0 7 AnalogX Proxy 4.0 6 AnalogX Proxy 4.0 5 AnalogX Proxy 4.0 4 AnalogX Proxy 4.0 3 AnalogX Proxy 4.0 2 AnalogX Proxy 4.0 1 AnalogX Proxy 4.0 |
| Not Vulnerable: | |
Discussion
AnalogX Proxy Socks4A Buffer Overflow Vulnerability
AnalogX Proxy is prone to a buffer overflow condition when attempting to handle malformed SOCKS4A requests (via TCP port 1080). This may be exploited to create a denial of service condition or to potentially execute arbitrary instructions with the privileges of the AnalogX Proxy process.
AnalogX Proxy is prone to a buffer overflow condition when attempting to handle malformed SOCKS4A requests (via TCP port 1080). This may be exploited to create a denial of service condition or to potentially execute arbitrary instructions with the privileges of the AnalogX Proxy process.
Exploit / POC
AnalogX Proxy Socks4A Buffer Overflow Vulnerability
The following was provided as an example of how to reproduce this issue:
Send a Sock4a request to the target system on TCP port 1080 consisting
of a hostname section of 140 or more characters will cause a write
access violation application error.
An example TCP packet to send is
\x04\x01\x04\x38\x00\x00\x00abcd\x00#\x00
where the '\xXX' characters signify their corresponding HEX binary values and
the '#' is substituted with the DNS name of 140 or more characters.
Exploit released by Kanatoko <[email protected]>.
The following was provided as an example of how to reproduce this issue:
Send a Sock4a request to the target system on TCP port 1080 consisting
of a hostname section of 140 or more characters will cause a write
access violation application error.
An example TCP packet to send is
\x04\x01\x04\x38\x00\x00\x00abcd\x00#\x00
where the '\xXX' characters signify their corresponding HEX binary values and
the '#' is substituted with the DNS name of 140 or more characters.
Exploit released by Kanatoko <[email protected]>.
Solution / Fix
AnalogX Proxy Socks4A Buffer Overflow Vulnerability
Solution:
It has been reported that the vendor has acknowledged this issue and will be offering solutions on their website.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that the vendor has acknowledged this issue and will be offering solutions on their website.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.