A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc9eba55df74a07b498819ba). A specially crafted HTTP or TLS packet can lead to arbitrary code execution. An attacker could send a malicious packet to trigger this vulnerability.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25076.json",
"cwe_ids": [
"CWE-120"
],
"cna_assigner": "talos",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "0.6.0-2"
},
{
"last_affected": "0.6.0-2"
},
{
"introduced": "Master 822bb80df9b7b345cc9eba55df74a07b498819ba"
},
{
"last_affected": "Master 822bb80df9b7b345cc9eba55df74a07b498819ba"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25076.json"
"2026-07-22T02:24:41Z"
[
{
"digest": {
"line_hashes": [
"138289543668888041713044531663319349476",
"212909470280196749271392918238573764830",
"263280346834296647149550233130201968128",
"192356876502373812635224961273018974547"
],
"threshold": 0.9
},
"id": "CVE-2023-25076-485dc03c",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/dlundquist/sniproxy/commit/f8d9a433fe22ab2fa15c00179048ab02ae23d583",
"signature_type": "Line",
"target": {
"file": "src/address.c"
}
},
{
"digest": {
"function_hash": "11457737832399041380681785089784245979",
"length": 2408.0
},
"id": "CVE-2023-25076-a3681126",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/dlundquist/sniproxy/commit/f8d9a433fe22ab2fa15c00179048ab02ae23d583",
"signature_type": "Function",
"target": {
"function": "new_address",
"file": "src/address.c"
}
}
]