PT-2017-12221 · Tinyproxy+1 · Tinyproxy+1

Orlitzky

·

Publicado

2017-07-30

·

Atualizado

2024-06-15

·

CVE-2017-11747

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tinyproxy versions 1.8.4 and earlier
Description The issue allows local users to potentially kill arbitrary processes by modifying the tinyproxy.pid file, which is created after privileges are dropped to a non-root account. This could be exploited before a root script executes a command to kill a process based on the pid file content.
Recommendations For Tinyproxy versions 1.8.4 and earlier, consider restricting access to the /run/tinyproxy/tinyproxy.pid file to prevent unauthorized modifications until a fix is available. As a temporary workaround, avoid using the "kill cat /run/tinyproxy/tinyproxy.pid" command in root scripts until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-11747
DLA-2163-1
OPENSUSE-SU-2024:0119-1
OPENSUSE-SU-2024:11465-1
USN-4808-1

Produtos afetados

Tinyproxy
Ubuntu