20020701 Foundstone Advisory - Buffer Overflow in AnalogX Proxy (fwd)mailing list
http://archives.neohapsis.com/archives/bugtraq/2002-07/0006.html CVE-2002-1001
AnalogX Proxy 4.0 - Socks4A Buffer Overflow
Record summary
CVE-2002-1001 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long HTTP request to TCP port 6588 or (2) a SOCKS 4A request to TCP port 1080 with a long DNS hostname.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAnalogX Proxy 4.0 - Socks4A Buffer OverflowExploitDB exploitby KanatokoNot analyzed1 file
References
7analogx.comConfirmation
http://www.analogx.com/contents/download/network/proxy.htm analogx-proxy-http-bo(9455)vdb entry
http://www.iss.net/security_center/static/9455.php analogx-proxy-socks4a-bo(9456)vdb entry
http://www.iss.net/security_center/static/9456.php 5138vdb entry
http://www.securityfocus.com/bid/5138 5139vdb entry
http://www.securityfocus.com/bid/5139 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1001