PT-2022-8295 · Pacparser+1 · Pacparser+1

Ripplehang

·

Published

2022-12-13

·

Updated

2024-02-01

·

CVE-2019-25078

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pacparser versions up to 1.3.x
Description A problematic vulnerability was found in pacparser, affecting the pacparser find proxy function of the file src/pacparser.c. The manipulation of the url argument leads to buffer overflow. This issue requires local attacking.
Recommendations For versions up to 1.3.x, upgrade to version 1.4.0 to address this issue. As a temporary workaround, consider restricting the use of the pacparser find proxy function until the upgrade is applied.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2019-25078
PYSEC-2022-43062

Affected Products

Debian
Pacparser