Summary
The remote host is missing an update to libproxy
announced via advisory DSA 2571-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202571-1
Insight
The Red Hat Security Response Team discovered that libproxy, a library for automatic proxy configuration management, applied insufficient validation to the Content-Length header sent by a server providing a proxy.pac file. Such remote server could trigger an integer overflow and consequently overflow an in-memory buffer.
For the stable distribution (squeeze), this problem has been fixed in version 0.3.1-2+squeeze1.
For the testing distribution (wheezy), and the unstable distribution (sid), this problem has been fixed in version 0.3.1-5.1.
We recommend that you upgrade your libproxy packages.
Severity
Classification
-
CVE CVE-2012-4505 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities