Описание
url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
A flaw was found in libproxy in versions 0.4 through 0.4.15. A remote HTTP server can trigger an uncontrolled recursion via a response composed of an infinite stream that lacks a newline character leading to a stack exhaustion. The highest threat from this vulnerability is to system availability.
Отчет
Red Hat has determined this flaw to be of moderate impact as the attack triggers an uncontrolled recursion beyond the attacker's control and results in a DoS, which can cause service disruptions but does not directly enable privilege escalation or arbitrary code execution.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | libproxy | Out of support scope | ||
| Red Hat Enterprise Linux 7 | libproxy | Out of support scope | ||
| Red Hat Enterprise Linux 8 | libproxy | Fixed | RHEA-2024:8852 | 05.11.2024 |
| Red Hat Enterprise Linux 8 | libproxy | Fixed | RHEA-2024:8852 | 05.11.2024 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | libproxy | Fixed | RHSA-2024:6205 | 03.09.2024 |
Показывать по
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a rem ...
url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
5.9 Medium
CVSS3