Vulnerability Name:

CVE-2002-1781 (CCN-8114)

Assigned:2002-02-07
Published:2002-02-07
Updated:2017-07-11
Summary:Multiple buffer overflows in DeleGate 7.7.0 through 7.8.1 allow remote attackers to execute arbitrary code, as demonstrated using a long USER command to the POP proxy.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: BUGTRAQ
Type: Vendor Advisory
20020207 [Global InterSec 2002012101] DeleGate Application Proxy - Multiple Vulnerabilities

Source: CCN
Type: BugTraq Mailing List, Tue Feb 12 2002 - 04:38:08 CST
Re: [Global InterSec 2002012101] DeleGate Application Proxy - Multiple Vulnerabilities

Source: MITRE
Type: CNA
CVE-2002-1781

Source: BUGTRAQ
Type: UNKNOWN
20020212 Re: [Global InterSec 2002012101] DeleGate Application Proxy - Multiple Vulnerabilities

Source: CCN
Type: DeleGate Web site
DeleGate Home Page (www.delegate.org)

Source: CCN
Type: Global InterSec LLC Advisory 2002012101
DeleGate Application Proxy - Multiple Vulnerabilities

Source: MISC
Type: Vendor Advisory
http://www.globalintersec.com/adv/delegate-2002012101.txt

Source: CCN
Type: OSVDB ID: 59759
DeleGate POP Proxy Multiple Command Remote Overflow

Source: BID
Type: UNKNOWN
4055

Source: CCN
Type: BID-4055
Delegate POP Proxy USER Buffer Overflow Vulnerability

Source: XF
Type: UNKNOWN
delegate-proxy-pop-bo(8114)

Source: XF
Type: UNKNOWN
delegate-proxy-pop-bo(8114)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:delegate:delegate:7.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:delegate:delegate:7.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:delegate:delegate:7.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:delegate:delegate:7.8.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:delegate:delegate:7.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:delegate:delegate:7.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:delegate:delegate:7.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:delegate:delegate:7.8.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    delegate delegate 7.7.0
    delegate delegate 7.7.1
    delegate delegate 7.8.0
    delegate delegate 7.8.1
    delegate delegate 7.7.0
    delegate delegate 7.7.1
    delegate delegate 7.8.0
    delegate delegate 7.8.1