Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.69602
Category:FreeBSD Local Security Checks
Title:FreeBSD Ports: tinyproxy
Summary:The remote host is missing an update to the system; as announced in the referenced advisory.
Description:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: tinyproxy

CVE-2011-1499
acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting
specifies a CIDR block, permits TCP connections from all IP addresses,
which makes it easier for remote attackers to hide the origin of web
traffic by leveraging the open HTTP proxy server.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
2.6

CVSS Vector:
AV:N/AC:H/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-1499
44274
http://secunia.com/advisories/44274
DSA-2222
http://www.debian.org/security/2011/dsa-2222
[oss-security] 20110407 CVE request: tinyproxy runs as an open proxy when attempting to restrict allowable IP ranges
http://openwall.com/lists/oss-security/2011/04/07/9
[oss-security] 20110408 Re: CVE request: tinyproxy runs as an open proxy when attempting to restrict allowable IP ranges
http://openwall.com/lists/oss-security/2011/04/08/3
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=621493
https://banu.com/bugzilla/show_bug.cgi?id=90
https://banu.com/cgit/tinyproxy/diff/?id=e8426f6662dc467bd1d827100481b95d9a4a23e4
https://bugzilla.redhat.com/show_bug.cgi?id=694658
tinyproxy-aclc-sec-bypass(67256)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67256
CopyrightCopyright (C) 2011 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.