PT-2024-3314 · Tinyproxy+3 · Tinyproxy+3

Dimitrios Tatsis

·

Published

2024-05-01

·

Updated

2025-08-22

·

CVE-2023-49606

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tinyproxy versions 1.10.0 through 1.11.1
Description A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy. This vulnerability can be triggered by a specially crafted HTTP header, leading to memory corruption and potentially allowing remote code execution. An attacker can exploit this issue by making an unauthenticated HTTP request. It is estimated that over 50,000 Tinyproxy instances are exposed to this vulnerability, with nearly 52,000 internet-exposed instances at risk.
Recommendations For Tinyproxy versions 1.10.0 through 1.11.1, update to version 1.11.2 or later to fix the vulnerability. As a temporary workaround, consider restricting access to the vulnerable HTTP Connection Headers parsing function until a patch is available. Avoid using the affected Tinyproxy versions in production environments, especially those exposed to the public internet, until the issue is resolved.

Exploit

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2024-7546
BDU:2024-03549
CVE-2023-49606
DLA-3892-1
DSA-5705-1
MGASA-2025-0003
OPENSUSE-SU-2024:0119-1
OPENSUSE-SU-2024:13943-1
USN-7190-1

Affected Products

Alt Linux
Linuxmint
Tinyproxy
Ubuntu