libproxy 'print_proxies()' Function Format String Vulnerability
BID:56712
Info
libproxy 'print_proxies()' Function Format String Vulnerability
| Bugtraq ID: | 56712 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5580 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2012 12:00AM |
| Updated: | Apr 13 2015 09:26PM |
| Credit: | Matthias Weckbecker |
| Vulnerable: |
libproxy libproxy 0.3.1 |
| Not Vulnerable: | |
Discussion
libproxy 'print_proxies()' Function Format String Vulnerability
libproxy is prone to a format-string vulnerability because it fails to properly sanitize user-supplied input before passing it as a format specifier to a formatted-printing function.
An attacker may exploit this issue to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely result in a denial-of-service condition.
libproxy 0.3.1 is vulnerable; other versions may also be affected.
libproxy is prone to a format-string vulnerability because it fails to properly sanitize user-supplied input before passing it as a format specifier to a formatted-printing function.
An attacker may exploit this issue to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely result in a denial-of-service condition.
libproxy 0.3.1 is vulnerable; other versions may also be affected.
References
libproxy 'print_proxies()' Function Format String Vulnerability
References:
References:
- Bug 791086 - VUL-0: libproxy: format string vulnerability (Bugzilla)
- libproxy Project HomePage (libproxy)