CVE-2012-5580
Publication date 27 October 2014
Last updated 24 July 2024
Ubuntu priority
Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as demonstrated using the http_proxy environment variable or a PAC file.
Status
Package | Ubuntu Release | Status |
---|---|---|
libproxy | ||
Notes
mdeslaur
only used in "proxy" tool in libproxy-tools package, and caught by FORTIFY_SOURCE. Reproducer from SUSE bug: http_proxy=http://foo%n.suse.de/ proxy http://foo.bar.de
Patch details
Package | Patch details |
---|---|
libproxy |