CVE-2025-34451

Name
CVE-2025-34451
Description
rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflow vulnerability in the function proxy_from_string() located in src/libproxychains.c. When parsing crafted proxy configuration entries containing overly long username or password fields, the application may write beyond the bounds of fixed-size stack buffers, leading to memory corruption or crashes. This vulnerability may allow denial of service and, under certain conditions, could be leveraged for further exploitation depending on the execution environment and applied mitigations.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
patch https://github.com/httpsgithu/proxychains-ng/commit/cc005b7
technical-description https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-008-proxychains-ng-stack-buffer-overflow-proxy_from_string.md
issue-tracking https://github.com/rofl0r/proxychains-ng/issues/606
third-party-advisory https://www.vulncheck.com/advisories/rofl0r-proxychains-ng-stack-based-buffer-overflow

Match rules

CPE URI Source package Min version Max version
proxychains-ng >= 0 <= 4.17
proxychains-ng == commit cc005b7 == None
cpe:2.3:a:proxychains-ng_project:proxychains-ng:*:*:*:*:*:*:*:* proxychains-ng >= None <= 4.17

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
proxychains-ng edge-main 4.17-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
proxychains-ng 3.23-main 4.17-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
proxychains-ng 3.22-main 4.17-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
proxychains-ng 3.21-main 4.17-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
proxychains-ng 3.20-main 4.17-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
proxychains-ng 3.19-main 4.16-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable