at32 Reverse Proxy Denial of Service Vulnerability


Description   demonalex has discovered a vulnerability in at32 Reverse Proxy, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to a NULL pointer dereference error when processing web requests and can be exploited to cause a crash via an overly long string within a HTTP header.
The vulnerability is confirmed in version 1.060.310. Other versions may also be affected.
     
Vulnerable Products   Vulnerable Software:
at32 Reverse Proxy 1.x
     
Solution   Restrict access to trusted hosts only.
     
CVE  
     
References   http://archives.neohapsis.com/archives/bugtraq/2012-03/0080.html
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Moderate 

 Vulnerability First Public Report Date 
2012-03-20 

 Target Type 
Server 

 Possible exploit 
Remote