OESA-2022-1756
Dashboard / Vulnerabilities / OESA-2022-1756
Summary: libproxy security update
Details: libproxy offers the following features:* extremely small core footprint (< 35k).* no external dependencies within libproxy core.(libproxy plugins may have dependencies).* only 3 functions in the stable external API.* dynamic adjustment to changing network topology.* a standard way of dealing with proxy settings across all scenarios. Security Fix(es): url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.(CVE-2020-25219)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1756, https://nvd.nist.gov/vuln/detail/CVE-2020-25219
Affected packages
Package
Name: libproxy
Purl: pkg:rpm/openEuler/libproxy&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
