CyberSec.Space Logo
CVEブラウザに戻る

CVE-2020-25219

HIGH
7.5
CVSS Severity Score
EPSS Score0.1730%
EPSS Percentile13.49th
Published2020年9月9日
Last Modified2024年11月21日

Vulnerability Description

url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.

Affected Platforms (CPE)

📦
Libproxy Project

Libproxy

>= 0.4.0 and <= 0.4.15
💻
Debian

Debian Linux

= 9.0
💻
Debian

Debian Linux

= 10.0
💻
Fedoraproject

Fedora

= 31
💻
Fedoraproject

Fedora

= 32
💻
Fedoraproject

Fedora

= 33
💻
Opensuse

Leap

= 15.1
💻
Opensuse

Leap

= 15.2
💻
Canonical

Ubuntu Linux

= 16.04
💻
Canonical

Ubuntu Linux

= 18.04
💻
Canonical

Ubuntu Linux

= 20.04

References & Advisories

関連する脆弱性情報