CVE-2023-49606: , CVE-2023-40533: memory safety vulnerabilities in tinyproxy <=1.11.1
A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49606?
CVE-2023-49606 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2023-49606?
To fix CVE-2023-49606, upgrade Tinyproxy to version 1.11.2 or later, or to versions 1.10.0-5+deb11u1 or 1.11.1-2.1+deb12u1.
What causes the vulnerability CVE-2023-49606?
CVE-2023-49606 is caused by a use-after-free vulnerability in the HTTP Connection Headers parsing of Tinyproxy.
Which versions of Tinyproxy are affected by CVE-2023-49606?
Affected versions of Tinyproxy include 1.10.0 up to 1.10.0-5 and 1.11.1 up to 1.11.1-2.1.
Can CVE-2023-49606 be exploited remotely?
Yes, CVE-2023-49606 can be exploited remotely, potentially allowing an attacker to execute arbitrary code.