CVE-2012-5580

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
27/10/2014
Last modified:
12/04/2025

Description

Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as demonstrated using the http_proxy environment variable or a PAC file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libproxy_project:libproxy:0.3.1:*:*:*:*:*:*:*