|
libproxy is prone to an overflow condition. The px_pac_reload() function fails to properly sanitize user-supplied input during the handling of content-length headers while downloading a proxy.pac auto-configuration file, which will result in a heap-based buffer overflow. With a specially crafted content-length header, a remote attacker can potentially execute arbitrary code via a Man-in-the-Middle attack.
|