Alerts This Week
Warning Icon 1 1,149
Alerts This Week
Warning Icon 1 1,149

Scientific Linux: CVE-2012-4505 Moderate: libproxy Buffer Overflow

Scientific Large Esm H446
Moderate: libproxy security update
Date: Thu, 15 Nov 2012 08:45:18 -0600
Reply-To: Pat Riehecky 
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Organization: Fermilab
Subject: Security ERRATA Moderate: libproxy on SL6.x i386/x86_64
MIME-Version: 1.0

Synopsis: Moderate: libproxy security update
Issue Date: 2012-11-14
CVE Numbers: CVE-2012-4505
--

A buffer overflow flaw was found in the way libproxy handled the
downloading of proxy auto-configuration (PAC) files. A malicious server
hosting a PAC file or a man-in-the-middle attacker could use this flaw to
cause an application using libproxy to crash or, possibly, execute
arbitrary code, if the proxy settings obtained by libproxy (from the
environment or the desktop environment settings) instructed the use of a
PAC proxy configuration. (CVE-2012-4505)

All applications using libproxy must be restarted for this update to
take effect.
--

SL6
 x86_64
 libproxy-0.3.0-3.el6_3.i686.rpm
 libproxy-0.3.0-3.el6_3.x86_64.rpm
 libproxy-bin-0.3.0-3.el6_3.x86_64.rpm
 libproxy-python-0.3.0-3.el6_3.x86_64.rpm
 libproxy-devel-0.3.0-3.el6_3.i686.rpm
 libproxy-devel-0.3.0-3.el6_3.x86_64.rpm
 libproxy-gnome-0.3.0-3.el6_3.x86_64.rpm
 libproxy-kde-0.3.0-3.el6_3.x86_64.rpm
 libproxy-mozjs-0.3.0-3.el6_3.x86_64.rpm
 libproxy-webkit-0.3.0-3.el6_3.x86_64.rpm
 i386
 libproxy-0.3.0-3.el6_3.i686.rpm
 libproxy-bin-0.3.0-3.el6_3.i686.rpm
 libproxy-python-0.3.0-3.el6_3.i686.rpm
 libproxy-devel-0.3.0-3.el6_3.i686.rpm
 libproxy-gnome-0.3.0-3.el6_3.i686.rpm
 libproxy-kde-0.3.0-3.el6_3.i686.rpm
 libproxy-mozjs-0.3.0-3.el6_3.i686.rpm
 libproxy-webkit-0.3.0-3.el6_3.i686.rpm

- Scientific Linux Development Team
Your message here