Tenable Network Security
Solutions Products Nessus Demos Partners Online Store
Nessus
Download
Plugins
     Newest Plugins
     Obtain an activation code
     View all plugins
     Search
Documentation
Register
Buy Now
ProfessionalFeed Support
Bugs
All the Tenable Products

3Proxy HTTP Proxy Crafted Transparent Request Remote Overflow

This script is Copyright (C) 2008-2010 Marcin Kozlowski

FamilyFirewalls
Nessus Plugin ID31094 (3proxy_logurl_overflow.nasl)
Bugtraq ID23545
CVE IDCVE-2007-2031

Description:
Synopsis :

The remote proxy is affected by a buffer overflow vulnerability.

Description :

The remote host is running 3proxy, an application proxy supporting
many protocols (Telnet, FTP, WWW, and more).

A stack overflow vulnerability has been detected in 3proxy prior to
0.5.3h and 0.6b-devel before 20070413. By sending a long host header
in HTTP GET request, a remote attacker could overflow a buffer and
execute arbitrary code.

See also :

http://3proxy.ru/0.5.3h/Changelog.txt
http://www.securityfocus.com/archive/1/archive/1/466650/100/100/threaded

Solution :

Upgrade to 3proxy version 0.5.3h or later.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
About Us | Jobs | Whitepapers | Training | Discussion Forums | Support Portal | Blog | RSS Feeds | Contact Us | Legal | Privacy

© Copyright 2002 - 2010 Tenable Network Security(R). All Rights Reserved.

This is the web site for the Nessus Vulnerability Scanner from Tenable Network Security. If you are looking for the probabilistic analysis software from Southwest Research Institute, please visit www.nessus.swri.org