CVE-2007-1866

dproxy dproxy-nexgen - Stack-based Buffer Overflow in dns_decode_reverse_name

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-1866. PoCs published by mu-b.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in dproxy-nexgen DNS proxy server, allowing remote code execution via a crafted UDP packet. It includes shellcode for a bind shell on port 4444 and supports multiple targets with specific frame pointer addresses.

Description

Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attackers to execute arbitrary code by sending a crafted packet to port 53/udp, a different issue than CVE-2007-1465.

Exploits (1)

exploitdb WORKING POC VERIFIED
by mu-b · cremotelinux_x86
https://www.exploit-db.com/exploits/3615

This exploit targets a buffer overflow vulnerability in dproxy-nexgen DNS proxy server, allowing remote code execution via a crafted UDP packet. It includes shellcode for a bind shell on port 4444 and supports multiple targets with specific frame pointer addresses.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: dproxy-nexgen (tar.gz and Debian stable versions)
No auth needed
Prerequisites: Network access to the target's DNS port (53/UDP) · Target must be running vulnerable dproxy-nexgen version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053289.html
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2518
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33753
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1194
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053302.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24688

Scores

EPSS 0.1018
EPSS Percentile 95.1%

Details

Status published
Products (1)
dproxy/dproxy nexgen
Published Apr 04, 2007
Tracked Since Feb 18, 2026