OSVDB ID: 86567

Title: libproxy url::get_pac() Function proxy.pac Auto-Configuration File Handling Remote Overflow

Info

Disclosure

Oct 22, 2012

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

libproxy is prone to an overflow condition. The url::get_pac() function fails to properly sanitize user-supplied input during the parsing of the proxy.pac auto-configuration file, which will reuslt in a stack-based buffer overflow. With a specially crafted auto-configuration file, a context-dependent attacker can potentially execute arbitrary code via a man-in-the-middle attack.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Third-Party Solution
Exploit: Exploit Unknown
Disclosure: Third-party Verified

Solution

SUSE has released updated packages to address this vulnerability. Check the vendor changelog in the references section. There are no known workarounds or upgrades to correct this issue.

Products

libproxy

libproxy

Unspecified

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/86567