PT-2025-48154 · Tinyproxy+2 · Tinyproxy+2

Published

2025-01-01

·

Updated

2026-03-10

·

CVE-2025-63938

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tinyproxy versions through 1.11.2
Description The software contains an integer overflow issue in the strip return port() function located within the src/reqs.c file. This can potentially lead to remote code execution.
Recommendations Update to a version later than 1.11.2. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-03627
CVE-2025-63938

Affected Products

Debian
Red Os
Tinyproxy