MidnightBSD

Advisories for libproxy_project

CVE-2012-4504 HIGH

Stack-based buffer overflow in the url::get_pac function in url.cpp in libproxy 0.4.x before 0.4.9 allows remote servers to have an unspecified impact via a large proxy.pac file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
libproxy_project libproxy 0.4.5
libproxy_project libproxy 0.4.0
libproxy_project libproxy 0.4.1
libproxy_project libproxy 0.4.7
libproxy_project libproxy 0.4.8
libproxy_project libproxy 0.4.6
libproxy_project libproxy 0.4.2
libproxy_project libproxy 0.4.3
CVE-2012-4505 HIGH

Heap-based buffer overflow in the px_pac_reload function in lib/pac.c in libproxy 0.2.x and 0.3.x allows remote servers to have an unspecified impact via a crafted Content-Length size in an HTTP response header for a proxy.pac file request, a different vulnerability than CVE-2012-4504.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
libproxy_project libproxy 0.2.3
libproxy_project libproxy 0.3.1
libproxy_project libproxy 0.3.0
CVE-2020-25219 MEDIUM

url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-674,

Products Affected

Vendor Product Version
canonical ubuntu_linux 20.04
debian debian_linux 9.0
debian debian_linux 10.0
opensuse leap 15.2
canonical ubuntu_linux 18.04
fedoraproject fedora 33
canonical ubuntu_linux 16.04
fedoraproject fedora 31
fedoraproject fedora 32
opensuse leap 15.1
libproxy_project libproxy *
CVE-2020-26154 MEDIUM

url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-120,

Products Affected

Vendor Product Version
debian debian_linux 9.0
debian debian_linux 10.0
opensuse leap 15.2
fedoraproject fedora 33
fedoraproject fedora 32
opensuse leap 15.1
libproxy_project libproxy *