CVE-2012-5580
published 2014-10-27CVE-2012-5580: Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.13%
86.4th percentile
Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as demonstrated using the http_proxy environment variable or a PAC file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libproxy | < libproxy 0.3.1-4 (bookworm) | libproxy 0.3.1-4 (bookworm) |
| libproxy_project | libproxy | — | — |
| libproxy_project | libproxy | >= 0 < 0.3.1-4 | 0.3.1-4 |
| libproxy_project | libproxy | >= 0 < 0.3.1-4 | 0.3.1-4 |
| libproxy_project | libproxy | >= 0 < 0.3.1-4 | 0.3.1-4 |
| libproxy_project | libproxy | >= 0 < 0.3.1-4 | 0.3.1-4 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libproxy: format string flaw in bin/proxy
vendor_redhat·2012-11-24·CVSS 7.5
CVE-2012-5580 [HIGH] libproxy: format string flaw in bin/proxy
libproxy: format string flaw in bin/proxy
Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as demonstrated using the http_proxy environment variable or a PAC file.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: libproxy (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2012-5580: libproxy - Format string vulnerability in the print_proxies function in bin/proxy.c in libp...
vendor_debian·2012·CVSS 7.5
CVE-2012-5580 [HIGH] CVE-2012-5580: libproxy - Format string vulnerability in the print_proxies function in bin/proxy.c in libp...
Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as demonstrated using the http_proxy environment variable or a PAC file.
Scope: local
bookworm: resolved (fixed in 0.3.1-4)
bullseye: resolved (fixed in 0.3.1-4)
forky: resolved (fixed in 0.3.1-4)
sid: resolved (fixed in 0.3.1-4)
trixie: resolved (fixed in 0.3.1-4)
GHSA
GHSA-mccr-h554-3wjw: Format string vulnerability in the print_proxies function in bin/proxy
ghsa_unreviewed·2022-05-17
CVE-2012-5580 [HIGH] CWE-94 GHSA-mccr-h554-3wjw: Format string vulnerability in the print_proxies function in bin/proxy
Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as demonstrated using the http_proxy environment variable or a PAC file.
OSV
CVE-2012-5580: Format string vulnerability in the print_proxies function in bin/proxy
osv·2014-10-27·CVSS 7.5
CVE-2012-5580 [HIGH] CVE-2012-5580: Format string vulnerability in the print_proxies function in bin/proxy
Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as demonstrated using the http_proxy environment variable or a PAC file.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/56712https://bugzilla.novell.com/show_bug.cgi?id=791086https://bugzilla.redhat.com/show_bug.cgi?id=883100https://code.google.com/p/libproxy/source/detail?r=475https://exchange.xforce.ibmcloud.com/vulnerabilities/80340http://www.securityfocus.com/bid/56712https://bugzilla.novell.com/show_bug.cgi?id=791086https://bugzilla.redhat.com/show_bug.cgi?id=883100https://code.google.com/p/libproxy/source/detail?r=475https://exchange.xforce.ibmcloud.com/vulnerabilities/80340
2014-10-27
Published