7.5
CVSSv2

CVE-2005-1857

Published: 02/09/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in simpleproxy prior to 3.4 allows remote malicious HTTP proxies to execute arbitrary code via format string specifiers in a reply.

Vulnerable Product Search on Vulmon Subscribe to Product

simpleproxy simpleproxy 3.0

simpleproxy simpleproxy 3.1

simpleproxy simpleproxy 2.2b

simpleproxy simpleproxy 3.2

Vendor Advisories

Ulf Härnhammar from the Debian Security Audit Project discovered a format string vulnerability in simpleproxy, a simple TCP proxy, that can be exploited via replies from remote HTTP proxies The old stable distribution (woody) is not affected For the stable distribution (sarge) this problem has been fixed in version 32-3sarge1 For the unstable ...