PT-2022-25392 · Tinyproxy+2 · Tinyproxy+2

Yikesoftware

·

Published

2022-09-19

·

Updated

2025-01-10

·

CVE-2022-40468

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tinyproxy versions prior to commit 84f203f
Description The issue is related to a potential leak of left-over heap data when custom error page templates containing special non-standard variables are used. This occurs because Tinyproxy commit 84f203f and earlier use uninitialized buffers in the process request() function.
Recommendations For versions prior to commit 84f203f, consider updating to a version that initializes buffers properly in the process request() function to prevent the potential leak of left-over heap data. As a temporary workaround, avoid using custom error page templates with special non-standard variables until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-40468
DLA-3892-1
MGASA-2025-0003
OPENSUSE-SU-2024:0119-1
OPENSUSE-SU-2024:12351-1
USN-7140-1
USN-7140-2

Affected Products

Linuxmint
Tinyproxy
Ubuntu