CVE-2020-26154
published 2020-09-30CVE-2020-26154: url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.57%
88.1th percentile
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libproxy | < libproxy 0.4.15-15 (bookworm) | libproxy 0.4.15-15 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libproxy_project | libproxy | <= 0.4.15 | — |
| libproxy_project | libproxy | >= 0 < 0.4.15-15 | 0.4.15-15 |
| libproxy_project | libproxy | >= 0 < 0.4.15-15 | 0.4.15-15 |
| libproxy_project | libproxy | >= 0 < 0.4.15-15 | 0.4.15-15 |
| libproxy_project | libproxy | >= 0 < 0.4.15-15 | 0.4.15-15 |
| msrc | cbl2_libproxy_0.4.17-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libproxy vulnerability
vendor_ubuntu·2021-01-04
CVE-2020-26154 libproxy vulnerability
Title: libproxy vulnerability
Summary: libproxy could be made to crash or execute arbitrary code if it received a specially
crafted file.
Li Fei discovered that libproxy incorrectly handled certain PAC files.
An attacker could possibly use this issue to cause a crash or execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled as demonstrated by a large PAC file that is delivered without a Content-length header.
vendor_msrc·2020-09-08·CVSS 9.8
CVE-2020-26154 [CRITICAL] CWE-120 url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled as demonstrated by a large PAC file that is delivered without a Content-length header.
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled as demonstrated by a large PAC file that is delivered without a Content-length header.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Marine
Red Hat
libproxy: sending more than 102400 bytes in PAC without a Content-Length present could result in buffer overflow
vendor_redhat·2020-07-16·CVSS 9.8
CVE-2020-26154 [CRITICAL] CWE-121 libproxy: sending more than 102400 bytes in PAC without a Content-Length present could result in buffer overflow
libproxy: sending more than 102400 bytes in PAC without a Content-Length present could result in buffer overflow
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
A vulnerability was found in libproxy, where a buffer overflow can occur if a server serving a PAC file sends more than 102400 bytes without a Content-Length header, this flaw allows an attacker to trigger an overflow of PAC_HTTP_BLOCK_SIZE (512 bytes), potentially leading to application crashes or unexpected behavior when processing large PAC files.
Statement: This vulnerability is rated as moderate because libproxy can overflow its buffer by PAC_HTTP_BLOCK_SIZE (512 bytes) if a server serving a PAC file
Debian
CVE-2020-26154: libproxy - url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is ena...
vendor_debian·2020·CVSS 9.8
CVE-2020-26154 [CRITICAL] CVE-2020-26154: libproxy - url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is ena...
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
Scope: local
bookworm: resolved (fixed in 0.4.15-15)
bullseye: resolved (fixed in 0.4.15-15)
forky: resolved (fixed in 0.4.15-15)
sid: resolved (fixed in 0.4.15-15)
trixie: resolved (fixed in 0.4.15-15)
GHSA
GHSA-49gc-vgp4-6qhm: url
ghsa_unreviewed·2022-05-24
CVE-2020-26154 [CRITICAL] CWE-120 GHSA-49gc-vgp4-6qhm: url
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
OSV
CVE-2020-26154: url
osv·2020-09-30·CVSS 9.8
CVE-2020-26154 [CRITICAL] CVE-2020-26154: url
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-26154 libproxy: sending more than 102400 bytes in PAC without a Content-Length present could result in buffer overflow [fedora-all]
bugzilla·2020-09-29·CVSS 9.8
CVE-2020-26154 [CRITICAL] CVE-2020-26154 libproxy: sending more than 102400 bytes in PAC without a Content-Length present could result in buffer overflow [fedora-all]
CVE-2020-26154 libproxy: sending more than 102400 bytes in PAC without a Content-Length present could result in buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2020-26154 libproxy: sending more than 102400 bytes in PAC without a Content-Length present could result in buffer overflow
bugzilla·2020-08-18·CVSS 9.8
CVE-2020-26154 [CRITICAL] CVE-2020-26154 libproxy: sending more than 102400 bytes in PAC without a Content-Length present could result in buffer overflow
CVE-2020-26154 libproxy: sending more than 102400 bytes in PAC without a Content-Length present could result in buffer overflow
It was found that if the server serving a PAC file sends more than 102400 bytes without a Content-Length present, libproxy can overflow its buffer by PAC_HTTP_BLOCK_SIZE (512) bytes.
References:
https://github.com/libproxy/libproxy/pull/126
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=968366
Discussion:
Created libproxy tracking bugs for this issue:
Affects: fedora-all [bug 1883584]
---
Is this issue ever going to be fixed in RHEL8 ?
Asking because I got asked to fix this in our RHEL8 based containers back on 2020/10/13 in https://issues.redhat.com/browse/CRW-1290 but as of UBI 8.6 the latest RPM is still
libproxy-0.4.15-5.2.el8
But according to ht
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00033.htmlhttps://bugs.debian.org/968366https://github.com/libproxy/libproxy/pull/126https://lists.debian.org/debian-lts-announce/2020/11/msg00024.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3BID3HVHAF6DA3YJOFDBSAZSMR3ODNIW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZVZXTFMFTSML3J6OOCDBDYH474BRJSW/https://www.debian.org/security/2020/dsa-4800http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00033.htmlhttps://bugs.debian.org/968366https://github.com/libproxy/libproxy/pull/126https://lists.debian.org/debian-lts-announce/2020/11/msg00024.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3BID3HVHAF6DA3YJOFDBSAZSMR3ODNIW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZVZXTFMFTSML3J6OOCDBDYH474BRJSW/https://www.debian.org/security/2020/dsa-4800
2020-09-30
Published