Buffer overflow in libproxy - CVE-2020-26154
Published: September 30, 2020 / Updated: October 16, 2020
Vulnerability identifier: #VU47695
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-26154
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
Affected software
libproxy
IBM QRadar Incident Forensics
libproxy (Debian package)
libproxy (Alpine package)
libproxy1v5 (Ubuntu package)
libproxy-webkitgtk4
libproxy-help
python2-libproxy
libproxy-devel
python3-libproxy
libproxy-debugsource
libproxy-debuginfo
libproxy
IBM Qradar SIEM
Opensuse
Ubuntu
openEuler
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
IBM QRadar Incident Forensics
libproxy (Debian package)
libproxy (Alpine package)
libproxy1v5 (Ubuntu package)
libproxy-webkitgtk4
libproxy-help
python2-libproxy
libproxy-devel
python3-libproxy
libproxy-debugsource
libproxy-debuginfo
libproxy
IBM Qradar SIEM
Opensuse
Ubuntu
openEuler
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
How to mitigate CVE-2020-26154
Install update from vendor's website.
libproxy (Debian package) - update to 0.4.15-5+deb10u1
libproxy (Alpine package) - update to 0.4.15-r9
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
libproxy1v5 (Ubuntu package) - addressed in versions 0.4.11-5ubuntu1.2, 0.4.15-1ubuntu0.2, 0.4.15-10ubuntu1.2, 0.4.15-13ubuntu1.1
libproxy-webkitgtk4 - update to 0.4.15-14
libproxy-help - update to 0.4.15-14
python2-libproxy - update to 0.4.15-14
libproxy-devel - update to 0.4.15-14
python3-libproxy - update to 0.4.15-14
libproxy-debugsource - update to 0.4.15-14
libproxy-debuginfo - update to 0.4.15-14
libproxy - update to 0.4.15-14
libproxy - addressed in versions 0.4.15-19.fc32, 0.4.15-25.fc33
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11
IBM QRadar Incident Forensics - update to 7.5.0.10
libproxy (Alpine package) - update to 0.4.15-r9
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
libproxy1v5 (Ubuntu package) - addressed in versions 0.4.11-5ubuntu1.2, 0.4.15-1ubuntu0.2, 0.4.15-10ubuntu1.2, 0.4.15-13ubuntu1.1
libproxy-webkitgtk4 - update to 0.4.15-14
libproxy-help - update to 0.4.15-14
python2-libproxy - update to 0.4.15-14
libproxy-devel - update to 0.4.15-14
python3-libproxy - update to 0.4.15-14
libproxy-debugsource - update to 0.4.15-14
libproxy-debuginfo - update to 0.4.15-14
libproxy - update to 0.4.15-14
libproxy - addressed in versions 0.4.15-19.fc32, 0.4.15-25.fc33
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11
IBM QRadar Incident Forensics - update to 7.5.0.10
External References
- https://bugs.debian.org/968366
- https://github.com/libproxy/libproxy/pull/126
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3BID3HVHAF6DA3YJOFDBSAZSMR3ODNIW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WZVZXTFMFTSML3J6OOCDBDYH474BRJSW/
Related Security Bulletins
- Buffer overflow in libproxy
- Buffer overflow in libproxy (Alpine package)
- OpenSUSE Linux update for libproxy
- OpenSUSE Linux update for libproxy
- Debian update for libproxy
- Remote code execution in VMware Tanzu Application Service for VMs and Isolation Segment
- Ubuntu update for libproxy
- openEuler 20.03 LTS update for libproxy
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in QRadar Incident Forensics
- Fedora 33 update for libproxy
- Fedora 32 update for libproxy