PT-2022-8295 · Pacparser+1 · Pacparser+1

·

CVE-2019-25078

·

Published

2022-12-13

·

Updated

2024-02-01

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pacparser versions up to 1.3.x
Description A problematic vulnerability was found in pacparser, affecting the pacparser find proxy function of the file src/pacparser.c. The manipulation of the url argument leads to buffer overflow. This issue requires local attacking.
Recommendations For versions up to 1.3.x, upgrade to version 1.4.0 to address this issue. As a temporary workaround, consider restricting the use of the pacparser find proxy function until the upgrade is applied.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25078
PYSEC-2022-43062

Affected Products

Debian
Pacparser