HTTP: Blue Coat Host Header Overflow

This signature detects attempts to exploit a known vulnerability against Blue Coat proxy appliance. Blue Coat Reporter 7.1.1.1 and earlier might be vulnerable. Attackers can craft a malicious HTTP request, which might allow them to gain control of the affected system with elevated privileges.

Extended Description

A remote buffer-overflow vulnerability affects Blue Coat Systems WinProxy because the application fails to properly validate the length of user-supplied strings before copying them into static process buffers. An attacker may exploit this issue to execute arbitrary code with the privileges of the vulnerable application. This may facilitate unauthorized access or privilege escalation. Blue Coat Systems WinProxy 6.0 is vulnerable to this issue; other versions may also be affected. Blue Coat Systems ProxyAV is also affected by this issue.

Affected Products

Blue_coat_systems proxyav,Blue_coat_systems webproxy

Short Name
HTTP:MISC:BLUECOAT-HOST-HDR-OF
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Blue CVE-2005-4085 Coat Header Host Overflow bid:16147
Release Date
06/01/2006
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3727
False Positive
Unknown
Vendors

Blue_coat_systems

CVSS Score

7.5

Found a potential security threat?