Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-34451

Опубликовано: 18 дек. 2025
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflow vulnerability in the function proxy_from_string() located in src/libproxychains.c. When parsing crafted proxy configuration entries containing overly long username or password fields, the application may write beyond the bounds of fixed-size stack buffers, leading to memory corruption or crashes. This vulnerability may allow denial of service and, under certain conditions, could be leveraged for further exploitation depending on the execution environment and applied mitigations.

A flaw was found in proxychains-ng. An attacker can exploit a stack-based buffer overflow vulnerability in the proxy_from_string() function by providing crafted proxy configuration entries containing overly long username or password fields. This can lead to memory corruption or application crashes, resulting in a Denial of Service (DoS). Under specific conditions, this vulnerability could potentially be leveraged for further exploitation.

Отчет

This vulnerability is rated Moderate for Red Hat as it can lead to a Denial of Service in proxychains-ng when processing crafted proxy configuration entries with overly long username or password fields. This component is available in Red Hat Community Projects (EPEL and Fedora) and requires an attacker to provide a malicious configuration file. Exploitation requires user interaction with a malicious configuration or a compromised configuration source.

Меры по смягчению последствий

Ensure that proxychains-ng configuration files are sourced only from trusted origins and are protected from unauthorized modification. If proxychains-ng is not essential for system operation, consider removing the package to eliminate the attack surface.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2423732proxychains-ng: proxychains-ng: Denial of Service due to stack-based buffer overflow via crafted proxy configuration

EPSS

Процентиль: 18%
0.0026
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
8 месяцев назад

rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflow vulnerability in the function proxy_from_string() located in src/libproxychains.c. When parsing crafted proxy configuration entries containing overly long username or password fields, the application may write beyond the bounds of fixed-size stack buffers, leading to memory corruption or crashes. This vulnerability may allow denial of service and, under certain conditions, could be leveraged for further exploitation depending on the execution environment and applied mitigations.

CVSS3: 7.8
nvd
8 месяцев назад

rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflow vulnerability in the function proxy_from_string() located in src/libproxychains.c. When parsing crafted proxy configuration entries containing overly long username or password fields, the application may write beyond the bounds of fixed-size stack buffers, leading to memory corruption or crashes. This vulnerability may allow denial of service and, under certain conditions, could be leveraged for further exploitation depending on the execution environment and applied mitigations.

CVSS3: 7.8
debian
8 месяцев назад

rofl0r/proxychains-ng versions up to and including 4.17 and prior to c ...

CVSS3: 7.8
github
8 месяцев назад

rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflow vulnerability in the function proxy_from_string() located in src/libproxychains.c. When parsing crafted proxy configuration entries containing overly long username or password fields, the application may write beyond the bounds of fixed-size stack buffers, leading to memory corruption or crashes. This vulnerability may allow denial of service and, under certain conditions, could be leveraged for further exploitation depending on the execution environment and applied mitigations.

EPSS

Процентиль: 18%
0.0026
Низкий

5 Medium

CVSS3