url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00030.html
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00033.html
https://github.com/libproxy/libproxy/issues/134
https://lists.debian.org/debian-lts-announce/2020/09/msg00012.html
Source: MITRE
Published: 2020-09-09
Updated: 2020-11-29
Type: CWE-787
Base Score: 5
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 10
Severity: MEDIUM
Base Score: 7.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 3.9
Severity: HIGH
OR
cpe:2.3:a:libproxy_project:libproxy:*:*:*:*:*:*:*:* versions from 0.4.0 to 0.4.15 (inclusive)
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
147089 | EulerOS Virtualization for ARM 64 3.0.6.0 : libproxy (EulerOS-SA-2021-1530) | Nessus | Huawei Local Security Checks | medium |
147081 | EulerOS Virtualization 3.0.6.6 : libproxy (EulerOS-SA-2021-1490) | Nessus | Huawei Local Security Checks | medium |
145127 | EulerOS 2.0 SP3 : libproxy (EulerOS-SA-2021-1087) | Nessus | Huawei Local Security Checks | medium |
144221 | EulerOS 2.0 SP5 : libproxy (EulerOS-SA-2020-2550) | Nessus | Huawei Local Security Checks | medium |
143650 | SUSE SLES12 Security Update : libproxy (SUSE-SU-2020:2900-1) | Nessus | SuSE Local Security Checks | medium |
143612 | SUSE SLED15 / SLES15 Security Update : libproxy (SUSE-SU-2020:2901-1) | Nessus | SuSE Local Security Checks | medium |
143313 | Debian DSA-4800-1 : libproxy - security update | Nessus | Debian Local Security Checks | medium |
142262 | EulerOS 2.0 SP2 : libproxy (EulerOS-SA-2020-2360) | Nessus | Huawei Local Security Checks | medium |
142180 | EulerOS 2.0 SP8 : libproxy (EulerOS-SA-2020-2304) | Nessus | Huawei Local Security Checks | medium |
141525 | openSUSE Security Update : libproxy (openSUSE-2020-1680) | Nessus | SuSE Local Security Checks | medium |
141513 | openSUSE Security Update : libproxy (openSUSE-2020-1676) | Nessus | SuSE Local Security Checks | medium |
141380 | EulerOS 2.0 SP9 : libproxy (EulerOS-SA-2020-2183) | Nessus | Huawei Local Security Checks | medium |
141141 | Fedora 31 : libproxy (2020-7e1e9abf77) | Nessus | Fedora Local Security Checks | medium |
140761 | Fedora 32 : libproxy (2020-2407cb0512) | Nessus | Fedora Local Security Checks | medium |
140643 | Ubuntu 16.04 LTS / 18.04 LTS / 20.04 LTS : libproxy vulnerability (USN-4514-1) | Nessus | Ubuntu Local Security Checks | medium |
140540 | Debian DLA-2372-1 : libproxy security update | Nessus | Debian Local Security Checks | medium |