Description
SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers to cause a denial of service by supplying an oversized string. Attackers can inject a large payload through the Proxy Server Host Name field in the Options menu to crash the application.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Hashim Jawad #
References
www.exploit-db.com/exploits/44372 (ExploitDB-44372)
www.vulncheck.com/...nial-of-service-via-proxy-configuration (VulnCheck Advisory: SysGauge 4.5.18 Local Denial of Service via Proxy Configuration)