AdSubtract Proxy ACL Bypass Connection Proxying Vulnerability
BID:7818
Info
AdSubtract Proxy ACL Bypass Connection Proxying Vulnerability
| Bugtraq ID: | 7818 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2003 12:00AM |
| Updated: | Jun 04 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Joe Stewart. |
| Vulnerable: |
AdSubtract AdSubtract Proxy 2.55 AdSubtract AdSubtract Proxy 2.54 AdSubtract AdSubtract Proxy 2.53 AdSubtract AdSubtract Proxy 2.52 AdSubtract AdSubtract Proxy 2.51 AdSubtract AdSubtract Proxy 2.50 |
| Not Vulnerable: | |
Discussion
AdSubtract Proxy ACL Bypass Connection Proxying Vulnerability
A vulnerability has been reported for AdSubtract Proxy. The problem occurs due to the application failing to handle specially crafted hostnames when carrying out reverse DNS lookups. By constructing a malicious hostname entry on a attacker-controlled DNS server, it may be possible for an attacker to bypass the access control list enforced by AdSubtract.
Successful exploitation of this vulnerability could allow an unauthorized remote user to anonymously proxy connections through the affected software.
A vulnerability has been reported for AdSubtract Proxy. The problem occurs due to the application failing to handle specially crafted hostnames when carrying out reverse DNS lookups. By constructing a malicious hostname entry on a attacker-controlled DNS server, it may be possible for an attacker to bypass the access control list enforced by AdSubtract.
Successful exploitation of this vulnerability could allow an unauthorized remote user to anonymously proxy connections through the affected software.
Solution / Fix
AdSubtract Proxy ACL Bypass Connection Proxying Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.