Back to search
CVE-2011-1499
Published: Apr 29, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=621493
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=694658
x_refsource_CONFIRM
44274
third-party-advisory
x_refsource_SECUNIA
tinyproxy-aclc-sec-bypass(67256)
vdb-entry
x_refsource_XF
https://banu.com/bugzilla/show_bug.cgi?id=90
x_refsource_CONFIRM
DSA-2222
vendor-advisory
x_refsource_DEBIAN
[oss-security] 20110407 CVE request: tinyproxy runs as an open proxy when attempting to restrict allowable IP ranges
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now