Back

HIGH

libproxy: uncontrolled recursion via an infinite stream response leading to stack exhaustion

Published Sep 9, 2020

Description

url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.

Affected products

Remediation

Red Hat statement

Red Hat has determined this flaw to be of moderate impact as the attack triggers an uncontrolled recursion beyond the attacker's control and results in a DoS, which can cause service disruptions but does not directly enable privilege escalation or arbitrary code execution.

Metrics

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 9, 2020
Updated Aug 4, 2024
Reserved Sep 9, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 9, 2020