Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 8 MGASA-2023-0178 Moderate Sniproxy Buffer Overflow

mageia
Calendar Grey May 21, 2023
Dist Mageia Esm H88
Recent updates to sniproxy packages are essential for addressing a buffer overflow security flaw identified on May 21, 2023.
A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy

Summary

A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy. A specially crafted HTTP or TLS packet can lead to arbitrary code execution. An attacker could send a malicious packet to trigger this vulnerability. (CVE-2023-25076)

References

- https://bugs.mageia.org/show_bug.cgi?id=31879

- https://lists.debian.org/debian-lts-announce/2023/04/msg00030.html

- https://www.cve.org/CVERecord?id=CVE-undefined

Resolution

SRPMS

- 8/core/sniproxy-0.6.1-1.mga8

Publication date: 21 May 2023
URL: https://advisories.mageia.org/MGASA-2023-0178.html
Type: security
CVE:

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here