[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

libproxy: pac server can trigger unbounded recursion in url.cpp recvline() (CVE-2020-25219)

ID: oval:org.secpod.oval:def:1802012Date: (C)2022-03-25   (M)2023-11-10
Class: PATCHFamily: unix




url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.

Platform:
Alpine Linux 3.12
Alpine Linux 3.13
Alpine Linux 3.14
Alpine Linux 3.15
Product:
libproxy
Reference:
11953
CVE-2020-25219
CVE    1
CVE-2020-25219
CPE    1
cpe:/a:libproxy_project:libproxy

© SecPod Technologies