First published: Sat Dec 31 2005(Updated: )
Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of packets with 0xFF characters to the Telnet port (TCP 23), which corrupts the heap.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bluecoat ProxySG | =4.0-r1a | |
Bluecoat ProxySG | =4.0-r1b | |
Bluecoat ProxySG | =4.0-r1c | |
Bluecoat ProxySG | =4.0-r1e | |
Bluecoat ProxySG | =4.0-r1f | |
Bluecoat ProxySG | =4.0-r1h | |
Bluecoat ProxySG | =4.0-r1k | |
Bluecoat ProxySG | =4.0-r1m | |
Bluecoat ProxySG | =4.0-r1n | |
Bluecoat ProxySG | =4.0-r1p | |
Bluecoat ProxySG | =5.0-r1a | |
Bluecoat ProxySG | =5.0-r1b | |
Bluecoat ProxySG | =5.0-r1c | |
Bluecoat ProxySG | =5.1-r1a | |
Bluecoat ProxySG | =5.1-r1d | |
Bluecoat ProxySG | =5.1-r1e | |
Bluecoat ProxySG | =5.2-r1a | |
Bluecoat ProxySG | =6.0-r1a | |
Bluecoat ProxySG | =6.0-r1c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3654 is considered a high severity vulnerability due to its potential to cause a denial of service and execute arbitrary code.
To fix CVE-2005-3654, you should upgrade your Blue Coat Systems Inc. WinProxy software to version 6.1a or later.
CVE-2005-3654 affects multiple versions of Bluecoat Webproxy including versions 4.0 and 5.0 before 6.1a.
CVE-2005-3654 can be exploited by sending a large number of packets with 0xFF characters to the Telnet port, resulting in a crash.
Yes, CVE-2005-3654 can lead to data loss as it may allow remote attackers to crash the affected system.