PT-2022-8295 · Pacparser+1 · Pacparser+1
Ripplehang
·
Published
2022-12-13
·
Updated
2024-02-01
·
CVE-2019-25078
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pacparser versions up to 1.3.x
Description
A problematic vulnerability was found in pacparser, affecting the
pacparser find proxy function of the file src/pacparser.c. The manipulation of the url argument leads to buffer overflow. This issue requires local attacking.Recommendations
For versions up to 1.3.x, upgrade to version 1.4.0 to address this issue. As a temporary workaround, consider restricting the use of the
pacparser find proxy function until the upgrade is applied.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Pacparser