Use-after-free in tinyproxy - CVE-2023-49606

 

Use-after-free in tinyproxy - CVE-2023-49606

Published: May 2, 2024 / Updated: August 9, 2024


Vulnerability identifier: #VU89115
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-49606
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the HTTP Connection Headers parsing. A remote attacker can send a specially crafted HTTP header and execute arbitrary code on the target system.


Affected software

tinyproxy
Debian Linux
Fedora
Ubuntu
tinyproxy (Ubuntu package)
tinyproxy-bin (Ubuntu package)
tinyproxy
tinyproxy (Debian package)

How to mitigate CVE-2023-49606

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

tinyproxy (Ubuntu package) - addressed in versions Ubuntu Pro, 1.10.0-4ubuntu0.2, 1.11.1-3ubuntu0.1
tinyproxy-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 1.10.0-4ubuntu0.2, 1.11.1-3ubuntu0.1
tinyproxy - addressed in versions 1.10.0-14.fc39, 1.11.2-1.el8, 1.11.2-1.el9, 1.11.2-1.fc40, 1.11.2-1.fc41, 1.11.2-2.el10_0
tinyproxy (Debian package) - update to 1.11.1-2.1+deb12u1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins