AOH :: HP Unsorted B :: TB11217.HTM

BlueCoat K9 Web Protection 3.2.36 Overflow



CSIS Advisory: BlueCoat K9 Web Protection 3.2.36 Overflow
CSIS Advisory: BlueCoat K9 Web Protection 3.2.36 Overflow



CSIS Security Group has discovered a remote exploitable arbitrary
overwrite, in the Blue Coat
K9 Web Protection local Web configuration manager on 127.0.0.1 and port
2372.

This allows an attacker to perform at least a Denial of Service
condition, on the
usage of internet.

Since the overflow can result in an overwrite of both the return address
and SHE, remote code
execution is possible.

Another attack vector could also be privilege escalation on the local
machine.

The Full advisory can be downloaded at: 
http://www.csis.dk/dk/forside/Bluecoat-k9.pdf 


Best regards
Dennis Rand
Malware/Security Researcher
CSIS Security Group
http://www.csis.dk 



The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.