Libproxy 'print _ proxies () 'function Format String Vulnerability
Release date:
Updated on:
Affected Systems:
Google libproxy 0.3.1
Description:
Bugtraq id: 56712
CVE (CAN) ID: CVE-2012-5580
Libproxy is a library that provides automatic proxy configuration management.
In libproxy 0.3.1, bin/proxy. the print_proxies function in c has the format string vulnerability. A context-independent attacker can exploit this vulnerability to cause denial of service and execute arbitrary code through the format string specifiers in the proxy name.
<* Source: Matthias Weckbecker
Link: http://xforce.iss.net/xforce/xfdb/80340
*>
Suggestion:
Vendor patch:
Google
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Https://code.google.com/p/libproxy/source/detail? R = 475.
This article permanently updates the link address: