CVE-2011-1843: Integer Overflow
Integer overflow in conf.c in Tinyproxy before 1.8.3 might allow remote attackers to bypass intended access restrictions in opportunistic circumstances via a TCP connection, related to improper handling of invalid port numbers.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1843?
The severity of CVE-2011-1843 is categorized as medium due to its potential exploitation to bypass access restrictions.
How do I fix CVE-2011-1843?
To fix CVE-2011-1843, upgrade Tinyproxy to version 1.8.3 or later, where this vulnerability is patched.
Which versions of Tinyproxy are affected by CVE-2011-1843?
CVE-2011-1843 affects Tinyproxy versions prior to 1.8.3, specifically versions including and below 1.7.2.
Can CVE-2011-1843 be exploited remotely?
Yes, CVE-2011-1843 can be exploited remotely through a TCP connection that manipulates invalid port numbers.
What type of vulnerability is CVE-2011-1843?
CVE-2011-1843 is classified as an integer overflow vulnerability, leading to unintended behavior in access control.