VulnerabilityModified
CVE-2011-1499
acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy…
LOW 2.6EPSS 1.75%
Does this matter?
Lower severity and a low EPSS score (1.75%). Track it; it rarely justifies an emergency change on its own.
Description
acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
- EPSS
- 1.75% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- banu/tinyproxy · debian/debian linux
- Source
- secalert@redhat.com
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=621493Issue Tracking, Patch
- http://openwall.com/lists/oss-security/2011/04/07/9Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2011/04/08/3Mailing List, Third Party Advisory
- http://secunia.com/advisories/44274
- http://www.debian.org/security/2011/dsa-2222Third Party Advisory
- https://banu.com/bugzilla/show_bug.cgi?id=90Broken Link
- https://banu.com/cgit/tinyproxy/diff/?id=e8426f6662dc467bd1d827100481b95d9a4a23e4Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=694658Issue Tracking, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67256
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=621493Issue Tracking, Patch
- http://openwall.com/lists/oss-security/2011/04/07/9Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2011/04/08/3Mailing List, Third Party Advisory
- http://secunia.com/advisories/44274
- http://www.debian.org/security/2011/dsa-2222Third Party Advisory
- https://banu.com/bugzilla/show_bug.cgi?id=90Broken Link
- https://banu.com/cgit/tinyproxy/diff/?id=e8426f6662dc467bd1d827100481b95d9a4a23e4Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=694658Issue Tracking, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67256
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.