CyberSec.Space Logo
Back to CVE Browser

CVE-2020-25219

HIGH
7.5
CVSS Severity Score
EPSS Score0.1730%
EPSS Percentile13.49th
PublishedSep 9, 2020
Last ModifiedNov 21, 2024

Vulnerability Description

url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.

Affected Platforms (CPE)

πŸ“¦
Libproxy Project

Libproxy

>= 0.4.0 and <= 0.4.15
πŸ’»
Debian

Debian Linux

= 9.0
πŸ’»
Debian

Debian Linux

= 10.0
πŸ’»
Fedoraproject

Fedora

= 31
πŸ’»
Fedoraproject

Fedora

= 32
πŸ’»
Fedoraproject

Fedora

= 33
πŸ’»
Opensuse

Leap

= 15.1
πŸ’»
Opensuse

Leap

= 15.2
πŸ’»
Canonical

Ubuntu Linux

= 16.04
πŸ’»
Canonical

Ubuntu Linux

= 18.04
πŸ’»
Canonical

Ubuntu Linux

= 20.04

References & Advisories

Related Vulnerabilities