• subscribe
May 29, 2003 12:00 AM

Buffer Overrun in AnalogX Proxy Server for Windows

Windows IT Pro
InstantDoc ID #39121

Reported May 26, 2003, by K.K. Mookhey.

 

 

VERSIONS AFFECTED

 

·         AnalogX 4.13 and earlier

 

DESCRIPTION

 

A vulnerability in AnalogX Proxy 4.13 and earlier can result in the execution of arbitrary code on the vulnerable system. This vulnerability stems from a buffer-overflow condition. If a malicious user connects to the vulnerable host on TCP Port 6588 and supplies a URL of greater than 340 characters, a buffer overrun is triggered on the vulnerable system. By supplying a specially crafted URL, an attacker can execute arbitrary code on the vulnerable system.

 

VENDOR RESPONSE

 

AnalogX has released version 4.14, which isn't vulnerable to this condition.

 

CREDIT                                                                                                       

 

Discovered by K. K. Mookhey.



ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here