Описание
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
A vulnerability was found in libproxy, where a buffer overflow can occur if a server serving a PAC file sends more than 102400 bytes without a Content-Length header, this flaw allows an attacker to trigger an overflow of PAC_HTTP_BLOCK_SIZE (512 bytes), potentially leading to application crashes or unexpected behavior when processing large PAC files.
Отчет
This vulnerability is rated as moderate because libproxy can overflow its buffer by PAC_HTTP_BLOCK_SIZE (512 bytes) if a server serving a PAC file sends more than 102400 bytes without a Content-Length header, specific conditions related to PAC file handling, and while it could lead to crashes or unexpected behavior, its overall impact is limited.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | libproxy | Not affected | ||
| Red Hat Enterprise Linux 7 | libproxy | Not affected | ||
| Red Hat Enterprise Linux 8 | libproxy | Fixed | RHEA-2024:8852 | 05.11.2024 |
| Red Hat Enterprise Linux 8 | libproxy | Fixed | RHEA-2024:8852 | 05.11.2024 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | libproxy | Fixed | RHSA-2024:6205 | 03.09.2024 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when ...
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
EPSS
7.5 High
CVSS3