Vulnerability Description
Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long HTTP request to TCP port 6588 or (2) a SOCKS 4A request to TCP port 1080 with a long DNS hostname.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Analogx | Proxy | 4.0 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0006.html
- http://www.analogx.com/contents/download/network/proxy.htm
- http://www.iss.net/security_center/static/9455.phpVendor Advisory
- http://www.iss.net/security_center/static/9456.phpVendor Advisory
- http://www.securityfocus.com/bid/5138ExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/5139ExploitPatchVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0006.html
- http://www.analogx.com/contents/download/network/proxy.htm
- http://www.iss.net/security_center/static/9455.phpVendor Advisory
- http://www.iss.net/security_center/static/9456.phpVendor Advisory
- http://www.securityfocus.com/bid/5138ExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/5139ExploitPatchVendor Advisory
FAQ
What is CVE-2002-1001?
CVE-2002-1001 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long HTTP request to TCP port 6588 or (2) a SOCKS 4A re...
How severe is CVE-2002-1001?
CVE-2002-1001 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1001?
Check the references section above for vendor advisories and patch information. Affected products include: Analogx Proxy.