url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is
enabled, as demonstrated by a large PAC file that is delivered without a
Content-length header. (CVE-2020-26154)
- https://bugs.mageia.org/show_bug.cgi?id=27411
- https://lists.suse.com/pipermail/sle-security-updates/2020-October/007540.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3BID3HVHAF6DA3YJOFDBSAZSMR3ODNIW/
- https://www.cve.org/CVERecord?id=CVE-2020-26154
- 7/core/libproxy-0.4.15-4.2.mga7
Get the latest Linux and open source security news straight to your inbox.