A vulnerability has been discovered in 3proxy, possibly resulting in a Denial of Service.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200711-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: 3proxy: Denial of Service Date: November 08, 2007 Bugs: #196772 ID: 200711-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been discovered in 3proxy, possibly resulting in a Denial of Service. Background ========= 3proxy is a really tiny cross-platform proxy servers set, including HTTP, HTTPS, FTP, SOCKS and POP3 support. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-proxy/3proxy < 0.5.3j > = 0.5.3j Description ========== 3proxy contains a double free vulnerability in the ftpprchild() function, which frees param-> hostname and calls the parsehostname() function, which in turn attempts to free param-> hostname again. Impact ===== A remote attacker could send a specially crafted request to the proxy, possibly resulting in a Denial of Service. Under typical configuration, the scope of this vulnerability is limited to the local network. Workaround ========= There is no known workaround at this time. Resolution ========= All 3proxy users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-proxy/3proxy-0.5.3j" References ========= [ 1 ] CVE-2007-5622 https://www.cve.org/CVERecord?id=CVE-2007-5622 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200711-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
A vulnerability has been discovered in 3proxy allowing for the remote execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200704-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: 3proxy: Buffer overflow Date: April 22, 2007 Bugs: #174429 ID: 200704-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been discovered in 3proxy allowing for the remote execution of arbitrary code. Background ========= 3proxy is a multi-protocol proxy, including HTTP/HTTPS/FTP and SOCKS support. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-proxy/3proxy < 0.5.3h > = 0.5.3h Description ========== The 3proxy development team reported a buffer overflow in the logurl() function when processing overly long requests. Impact ===== A remote attacker could send a specially crafted transparent request to the proxy, resulting in the execution of arbitrary code with privileges of the user running 3proxy. Workaround ========= There is no known workaround at this time. Resolution ========= All 3proxy users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-proxy/3proxy-0.5.3h" References ========= [ 1 ] CVE-2007-2031 https://www.cve.org/CVERecord?id=CVE-2007-2031 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200704-17 Concerns? ======== Securityis a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.