CVE-2012-3505: Medium severity banu Tinyproxy vulnerability
Tinyproxy 1.8.3 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via (1) a large number of headers or (2) a large number of forged headers that trigger hash collisions predictably. bucket.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3505?
CVE-2012-3505 has a moderate severity level due to its potential to cause denial of service through CPU and memory exhaustion.
How do I fix CVE-2012-3505?
To mitigate CVE-2012-3505, upgrade Tinyproxy to version 1.8.4 or later which addresses this vulnerability.
What are the impacts of CVE-2012-3505?
CVE-2012-3505 allows remote attackers to exhaust CPU and memory resources, potentially leading to service disruption.
Which versions of Tinyproxy are affected by CVE-2012-3505?
Tinyproxy versions 1.8.3 and earlier are affected by CVE-2012-3505.
Can CVE-2012-3505 be exploited remotely?
Yes, CVE-2012-3505 can be exploited remotely by attackers through the submission of crafted HTTP headers.