PT-2005-1024 · Debian · Simpleproxy

Ulf Harnhammar

·

Published

2005-09-02

·

Updated

2017-07-11

·

CVE-2005-1857

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions simpleproxy versions prior to 3.4
Description The issue concerns multiple vulnerabilities in the simpleproxy package of the Debian GNU/Linux operating system, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. A format string vulnerability allows remote malicious HTTP proxies to execute arbitrary code via format string specifiers in a reply.
Recommendations For versions prior to 3.4, update to version 3.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the simpleproxy package to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02864
CVE-2005-1857
DSA-786-1

Affected Products

Simpleproxy