PT-2025-52353 · Rofl0R+1 · Proxychains-Ng+1
Vlatko Kosturjak
·
Published
2025-12-18
·
Updated
2026-01-06
·
CVE-2025-34451
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7
Description
The software contains a stack-based buffer overflow in the
proxy from string() function, located in src/libproxychains.c. This occurs when parsing proxy configuration entries with excessively long username or password fields. The application may write beyond the bounds of stack buffers, potentially causing memory corruption or crashes. This may lead to denial of service and, depending on the environment, could be leveraged for further exploitation.Recommendations
Update to a version after commit cc005b7.
Exploit
Fix
DoS
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Proxychains-Ng