PT-2012-1178 · Libproxy · Libproxy

Tomas Mraz

·

Published

2012-11-11

·

Updated

2024-06-15

·

CVE-2012-4504

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libproxy versions 0.4.x through 0.4.9
Description The issue is related to a stack-based buffer overflow in the url::get pac function, which can be triggered by a large proxy.pac file from remote servers. This may lead to unspecified consequences. The vulnerability can be exploited remotely and may result in a breach of confidentiality, integrity, and availability of protected information.
Recommendations For libproxy versions 0.4.x through 0.4.9, update to version 0.4.9 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09719
CVE-2012-4504
OPENSUSE-SU-2024:10327-1

Affected Products

Libproxy