Oval Definition:oval:com.redhat.rhsa:def:20121461
Revision Date:2012-11-14Version:634
Title:RHSA-2012:1461: libproxy security update (Moderate)
Description:libproxy is a library that handles all the details of proxy configuration.

  • A buffer overflow flaw was found in the way libproxy handled the downloading of proxy auto-configuration (PAC) files. A malicious server hosting a PAC file or a man-in-the-middle attacker could use this flaw to cause an application using libproxy to crash or, possibly, execute arbitrary code, if the proxy settings obtained by libproxy (from the environment or the desktop environment settings) instructed the use of a PAC proxy configuration. (CVE-2012-4505)

    This issue was discovered by the Red Hat Security Response Team.

    Users of libproxy should upgrade to these updated packages, which contain a backported patch to correct this issue. All applications using libproxy must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-4505
    CVE-2012-4505
    RHSA-2012:1461
    RHSA-2012:1461-01
    RHSA-2012:1461-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • libproxy is earlier than 0:0.3.0-3.el6_3
  • AND libproxy is signed with Red Hat redhatrelease2 key
  • libproxy-bin is earlier than 0:0.3.0-3.el6_3
  • AND libproxy-bin is signed with Red Hat redhatrelease2 key
  • libproxy-devel is earlier than 0:0.3.0-3.el6_3
  • AND libproxy-devel is signed with Red Hat redhatrelease2 key
  • libproxy-gnome is earlier than 0:0.3.0-3.el6_3
  • AND libproxy-gnome is signed with Red Hat redhatrelease2 key
  • libproxy-kde is earlier than 0:0.3.0-3.el6_3
  • AND libproxy-kde is signed with Red Hat redhatrelease2 key
  • libproxy-mozjs is earlier than 0:0.3.0-3.el6_3
  • AND libproxy-mozjs is signed with Red Hat redhatrelease2 key
  • libproxy-python is earlier than 0:0.3.0-3.el6_3
  • AND libproxy-python is signed with Red Hat redhatrelease2 key
  • libproxy-webkit is earlier than 0:0.3.0-3.el6_3
  • AND libproxy-webkit is signed with Red Hat redhatrelease2 key
  • BACK