CVE-2025-34451

rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflow vulnerability in the function proxy_from_string() located in src/libproxychains.c. When parsing crafted proxy configuration entries containing overly long username or password fields, the application may write beyond the bounds of fixed-size stack buffers, leading to memory corruption or crashes. This vulnerability may allow denial of service and, under certain conditions, could be leveraged for further exploitation depending on the execution environment and applied mitigations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:proxychains-ng_project:proxychains-ng:*:*:*:*:*:*:*:*

History

31 Dec 2025, 17:45

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:proxychains-ng_project:proxychains-ng:*:*:*:*:*:*:*:*
First Time Proxychains-ng Project
Proxychains-ng Project proxychains-ng
CWE CWE-787
References () https://github.com/httpsgithu/proxychains-ng/commit/cc005b7 - () https://github.com/httpsgithu/proxychains-ng/commit/cc005b7 - Patch
References () https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-008-proxychains-ng-stack-buffer-overflow-proxy_from_string.md - () https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-008-proxychains-ng-stack-buffer-overflow-proxy_from_string.md - Exploit, Third Party Advisory
References () https://github.com/rofl0r/proxychains-ng/issues/606 - () https://github.com/rofl0r/proxychains-ng/issues/606 - Exploit, Patch
References () https://www.vulncheck.com/advisories/rofl0r-proxychains-ng-stack-based-buffer-overflow - () https://www.vulncheck.com/advisories/rofl0r-proxychains-ng-stack-based-buffer-overflow - Third Party Advisory

18 Dec 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-18 22:15

Updated : 2025-12-31 17:45


NVD link : CVE-2025-34451

Mitre link : CVE-2025-34451

CVE.ORG link : CVE-2025-34451


JSON object : View

Products Affected

proxychains-ng_project

  • proxychains-ng
CWE
CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write