Out-of-bounds write in libproxy - CVE-2020-25219

 

Out-of-bounds write in libproxy - CVE-2020-25219

Published: September 9, 2020 / Updated: September 15, 2020


Vulnerability identifier: #VU46729
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25219
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.


Affected software

libproxy
IBM QRadar Incident Forensics
Arch Linux
Opensuse
Ubuntu
openEuler
Fedora
libproxy (Debian package)
libproxy (Alpine package)
libproxy1v5 (Ubuntu package)
libproxy
libproxy-webkitgtk4
libproxy-help
python2-libproxy
python3-libproxy
libproxy-devel
libproxy-debugsource
libproxy-debuginfo
IBM Qradar SIEM

How to mitigate CVE-2020-25219

Install update from vendor's website.

libproxy (Debian package) - update to 0.4.15-5+deb10u1
libproxy (Alpine package) - update to 0.4.15-r8
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
libproxy1v5 (Ubuntu package) - addressed in versions 0.4.11-5ubuntu1.1, 0.4.15-1ubuntu0.1, 0.4.15-10ubuntu1.1
libproxy - addressed in versions 0.4.15-15.fc31, 0.4.15-18.fc32, 0.4.15-24.fc33
libproxy-webkitgtk4 - update to 0.4.15-18
libproxy-help - update to 0.4.15-18
python2-libproxy - update to 0.4.15-18
python3-libproxy - update to 0.4.15-18
libproxy-devel - update to 0.4.15-18
libproxy-debugsource - update to 0.4.15-18
libproxy-debuginfo - update to 0.4.15-18
libproxy - update to 0.4.15-18
IBM QRadar Incident Forensics - update to 7.5.0.10

External References

Related Security Bulletins