Configuration in tinyproxy and Debian Linux - CVE-2011-1499

 

Configuration in tinyproxy and Debian Linux - CVE-2011-1499

Published: April 30, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45103
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-1499
CWE-ID: CWE-16
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.


Affected software

tinyproxy
Debian Linux
Fedora
tinyproxy

How to mitigate CVE-2011-1499

Install update from vendor's website.

tinyproxy - update to 1.8.3-1.el6

External References

Related Security Bulletins