Home page logo

oss-sec logo oss-sec mailing list archives

Re: libproxy PAC downloading buffer overflows
From: Matthias Weckbecker <mweckbecker () suse de>
Date: Fri, 12 Oct 2012 16:02:57 +0200

On Friday 12 October 2012 15:46:47 Kurt Seifried wrote:
On 10/12/2012 02:43 AM, Tomas Hoger wrote:

libproxy 0.4.9 fixes a buffer overflow reported by Tomas Mraz:



Upstream announcement also mentions another issue - CVE-2012-4505.
It is related, but different problem that was found in pre-0.4
versions while investigating if they were affected by


Please use CVE-2012-4521 for this issue.

Wasn't this rather a CVE notification than a CVE request? At least 
it looked like this to me. The announcement mentions two CVE.


Matthias Weckbecker, Senior Security Engineer, SUSE Security Team
SUSE LINUX Products GmbH, Maxfeldstr. 5, D-90409 Nuernberg, Germany
Tel: +49-911-74053-0;  http://suse.com/
SUSE LINUX Products GmbH, GF: Jeff Hawn, HRB 16746 (AG Nuernberg) 

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]