SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#139421

simpleproxy format string vulnerability

Overview

A format string vulnerability in the simpleproxy TCP proxy may allow a remote attacker to execute arbitrary code on a vulnerable system.

I. Description

simpleproxy, a basic open source TCP proxy, contains a format string vulnerability in an unspecified HTTP proxy request handling routine. If a remote attacker sends simpleproxy a specially crafted HTTP request, they may be able to execute arbitrary code on a vulnerable system.

II. Impact

A remote attacker may be able to execute arbitrary code with the privileges of the simpleproxy process.

III. Solution

Upgrade

Upgrading to simpleproxy version 3.4 corrects this problem.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Not Vulnerable10-Oct-2005
Conectiva Inc.Unknown2-Sep-2005
Cray, Inc.Unknown2-Sep-2005
Debian LinuxVulnerable2-Sep-2005
EMC, Inc. (formerly Data General Corporation)Unknown2-Sep-2005
Engarde Secure LinuxUnknown2-Sep-2005
F5 Networks, Inc.Unknown2-Sep-2005
FreeBSD, Inc.Unknown2-Sep-2005
Fujitsu LimitedUnknown2-Sep-2005
Hewlett-Packard CompanyUnknown2-Sep-2005
Hitachi InternetworkingUnknown2-Sep-2005
IBM CorporationUnknown2-Sep-2005
IBM Corporation (zseries)Unknown2-Sep-2005
IBM eServerUnknown2-Sep-2005
Immunix Communications, Inc.Unknown2-Sep-2005
Ingrian, Inc.Unknown2-Sep-2005
Juniper Networks, Inc.Unknown2-Sep-2005
Mandriva, Inc.Unknown2-Sep-2005
Microsoft CorporationUnknown2-Sep-2005
MontaVista SoftwareUnknown2-Sep-2005
NECUnknown2-Sep-2005
NetBSDUnknown2-Sep-2005
NovellUnknown2-Sep-2005
OpenBSDUnknown2-Sep-2005
OpenWall LinuxNot Vulnerable6-Sep-2005
QNX, Software Systems, Inc.Unknown2-Sep-2005
Red Hat Software, Inc.Unknown2-Sep-2005
Sequent Computer Systems, Inc.Unknown2-Sep-2005
Silicon Graphics, Inc.Unknown2-Sep-2005
simpleproxyVulnerable1-Sep-2005
Sony CorporationUnknown2-Sep-2005
Sun Microsystems, Inc.Not Vulnerable6-Sep-2005
SuSeUnknown2-Sep-2005
The SCO Group (SCO Linux)Unknown2-Sep-2005
The SCO Group (SCO UnixWare)Unknown2-Sep-2005
TurbolinuxUnknown2-Sep-2005
UNISYSUnknown2-Sep-2005
Wind River SystemsUnknown2-Sep-2005

References


http://secunia.com/advisories/16567/
http://www.us.debian.org/security/2005/dsa-786
http://sourceforge.net/projects/simpleproxy

Credit

This vulnerability was reported by Ulf Harnhammar.

This document was written by Jeff Gennari.

Other Information

Date Public:2005-08-26
Date First Published:2005-09-02
Date Last Updated:2005-10-10
CERT Advisory: 
CVE-ID(s):CAN-2005-1857
NVD-ID(s):CAN-2005-1857
US-CERT Technical Alerts: 
Metric:5.84
Document Revision:19

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2005 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader