AnalogX Proxy Web Proxy Buffer Overflow Vulnerability
BID:5139
Info
AnalogX Proxy Web Proxy Buffer Overflow Vulnerability
| Bugtraq ID: | 5139 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1001 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Discovery of this issue is credited to "Foundstone Labs" <[email protected]>. |
| Vulnerable: |
AnalogX Proxy 4.0 7 AnalogX Proxy 4.0 6 AnalogX Proxy 4.0 5 AnalogX Proxy 4.0 4 AnalogX Proxy 4.0 3 AnalogX Proxy 4.0 2 AnalogX Proxy 4.0 1 AnalogX Proxy 4.0 |
| Not Vulnerable: | |
Discussion
AnalogX Proxy Web Proxy Buffer Overflow Vulnerability
AnalogX Proxy is prone to a buffer overflow condition when attempting to handle malformed HTTP proxy requests (via TCP port 6588). This may be exploited to create a denial of service condition or to potentially execute arbitrary instructions with the privileges of the AnalogX Proxy process.
AnalogX Proxy is prone to a buffer overflow condition when attempting to handle malformed HTTP proxy requests (via TCP port 6588). This may be exploited to create a denial of service condition or to potentially execute arbitrary instructions with the privileges of the AnalogX Proxy process.
Exploit / POC
AnalogX Proxy Web Proxy Buffer Overflow Vulnerability
The following was provided as an example of how to reproduce this issue:
Send a HTTP proxy request to the target system on TCP port 6588 consisting of a single space character followed by 320 or more non-space characters followed by 2 carriage-return linefeeds causes a read access violation in the application.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following was provided as an example of how to reproduce this issue:
Send a HTTP proxy request to the target system on TCP port 6588 consisting of a single space character followed by 320 or more non-space characters followed by 2 carriage-return linefeeds causes a read access violation in the application.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
AnalogX Proxy Web Proxy Buffer Overflow Vulnerability
Solution:
It has been reported that the vendor has acknowledged this issue and will be offering solutions on their website.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that the vendor has acknowledged this issue and will be offering solutions on their website.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.