PT-2012-1178 · Libproxy · Libproxy

Tomas Mraz

·

Publicado

2012-11-11

·

Atualizado

2024-06-15

·

CVE-2012-4504

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libproxy versions 0.4.x through 0.4.9
Description The issue is related to a stack-based buffer overflow in the url::get pac function, which can be triggered by a large proxy.pac file from remote servers. This may lead to unspecified consequences. The vulnerability can be exploited remotely and may result in a breach of confidentiality, integrity, and availability of protected information.
Recommendations For libproxy versions 0.4.x through 0.4.9, update to version 0.4.9 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09719
CVE-2012-4504
OPENSUSE-SU-2024:10327-1

Produtos afetados

Libproxy