7.5
CVSSv2

CVE-2002-1930

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in AN HTTPd 1.38 up to and including 1.4.1c allows remote malicious users to execute arbitrary code via a SOCKS4 request with a long username.

Vulnerable Product Search on Vulmon Subscribe to Product

an an-httpd 1.38

an an-httpd 1.39

an an-httpd 1.41

an an-httpd 1.41c

an an-httpd 1.40

an an-httpd 1.41b

Exploits

source: wwwsecurityfocuscom/bid/6012/info A buffer overflow vulnerability has been reported for AN HTTPD The vulnerability is due to insufficient bounds checking of usernames for SOCKS4 requests When AN HTTPD acts as a SOCKS4 server, it handles user names in an unsafe manner An attacker can exploit this vulnerability by sending an ove ...