DeleGate HTTP Proxy Robot.TXT User-Agent: Buffer Overflow Vulnerability
BID:7054
Info
DeleGate HTTP Proxy Robot.TXT User-Agent: Buffer Overflow Vulnerability
| Bugtraq ID: | 7054 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2003 12:00AM |
| Updated: | Mar 10 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Keigo Yamazaki. |
| Vulnerable: |
DeleGate DeleGate 8.4 .0 DeleGate DeleGate 8.3.4 DeleGate DeleGate 8.3.3 DeleGate DeleGate 7.9.11 |
| Not Vulnerable: |
DeleGate DeleGate 8.5 .0 |
Discussion
DeleGate HTTP Proxy Robot.TXT User-Agent: Buffer Overflow Vulnerability
The DeleGate HTTP Proxy component is prone to a remotely exploitable buffer overflow vulnerability. This is due to insufficient bounds checking of User-Agent: fields in remote 'robot.txt' files. Successful exploitation may result in execution of malicious code in the security context of the DeleGate proxy server.
This issue was reported in DeleGate versions 8.3.4 and 8.4.0. Other versions may also be affected.
The DeleGate HTTP Proxy component is prone to a remotely exploitable buffer overflow vulnerability. This is due to insufficient bounds checking of User-Agent: fields in remote 'robot.txt' files. Successful exploitation may result in execution of malicious code in the security context of the DeleGate proxy server.
This issue was reported in DeleGate versions 8.3.4 and 8.4.0. Other versions may also be affected.
Exploit / POC
DeleGate HTTP Proxy Robot.TXT User-Agent: Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
DeleGate HTTP Proxy Robot.TXT User-Agent: Buffer Overflow Vulnerability
Solution:
OpenPKG have released an advisory (OpenPKG-SA-2003.023) and fixes that address this vulnerability.
This issue has been addressed in DeleGate 8.5.0.
DeleGate DeleGate 7.9.11
DeleGate DeleGate 8.3.3
DeleGate DeleGate 8.3.4
DeleGate DeleGate 8.4 .0
Solution:
OpenPKG have released an advisory (OpenPKG-SA-2003.023) and fixes that address this vulnerability.
This issue has been addressed in DeleGate 8.5.0.
DeleGate DeleGate 7.9.11
-
OpenPKG delegate-7.9.11-1.1.1.src.rpm
OpenPKG 1.1
ftp://ftp.openpkg.org/release/1.1/UPD/delegate-7.9.11-1.1.1.src.rpm
DeleGate DeleGate 8.3.3
-
OpenPKG delegate-8.3.3-1.2.1.src.rpm
OpenPKG 1.2
ftp://ftp.openpkg.org/release/1.2/UPD/delegate-8.3.3-1.2.1.src.rpm
DeleGate DeleGate 8.3.4
-
DeleGate DeleGate 8.5.0
http://www.delegate.org/delegate/download/
DeleGate DeleGate 8.4 .0
-
DeleGate DeleGate 8.5.0
http://www.delegate.org/delegate/download/
References
DeleGate HTTP Proxy Robot.TXT User-Agent: Buffer Overflow Vulnerability
References:
References:
- DeleGate (DeleGate)
- SNS Advisory No.63 (SNS)