Where
-Infinity
0
Severity
6.8
Integer Overflow
AV:N/AC:M/Au:N/C:P/I:P/A:P

Integer overflow in conf.c in Tinyproxy before 1.8.3 might allow remote attackers to bypass intended access restrictions in opportunistic circumstances via a TCP connection, related to improper handling of invalid port numbers.

First published (updated )
Severity
2.6
AV:N/AC:H/Au:N/C:N/I:P/A:N

acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.

1 / 2
Source: MITRE
First published (updated )
Severity
1

It was reported [1] that tinyproxy prior to version 1.8.3, when configured to allow a network range (i.e. "Allow 192.168.0.0/24" versus the default "Allow 127.0.0.1"), would allow any connections from any IP address, turning it into an open proxy. If tinyproxy were configured with one or more Allow statements that use an IP range, this would occur.

This has been fixed upstream [2] and affects the versions of tinyproxy as provided by Fedora and EPEL.

[1] https://banu.com/bugzilla/showbug.cgi?id=90 [2] https://banu.com/cgit/tinyproxy/commit/?id=e8426f6662dc467bd1d827100481b95d9a4a23e4

First published (updated )

Rejected reason: This CVE ID is a duplicate of CVE-2022-40468

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203