J-Security Center

Title: AnalogX Proxy Web Proxy Buffer Overflow Vulnerability

Severity: CRITICAL

Description:

AnalogX Proxy is proxy server software for Microsoft Windows operating systems.

AnalogX Proxy is prone to a buffer overflow condition when attempting to handle malformed HTTP proxy requests (via TCP port 6588). Requests must be specially crafted to contain a space character followed by 320+ non-space characters, followed by 2 carriage-return linefeeds (CRLF).

This may be exploited to create a denial of service condition. When the malformed request is received by the proxy, an error message will appear on the screen. Multiple malformed requests may cause the service to stop responding. Additionally, it may be possible to exploit this issue to execute arbitrary attacker-supplied instructions as the proxy server process.

Affected Products:

  • AnalogX Proxy 4.0.0
  • AnalogX Proxy 4.0.0 1
  • AnalogX Proxy 4.0.0 2
  • AnalogX Proxy 4.0.0 3
  • AnalogX Proxy 4.0.0 4
  • AnalogX Proxy 4.0.0 5
  • AnalogX Proxy 4.0.0 6
  • AnalogX Proxy 4.0.0 7

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.