CVE-2011-1499
published 2011-04-29CVE-2011-1499: acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it…
PriorityP411low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
1.75%
75.8th percentile
acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| banu | tinyproxy | <= 1.8.2 | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | >= 0 < 1.8.2-2 | 1.8.2-2 |
| banu | tinyproxy | >= 0 < 1.8.2-2 | 1.8.2-2 |
| banu | tinyproxy | >= 0 < 1.8.2-2 | 1.8.2-2 |
| banu | tinyproxy | >= 0 < 1.8.2-2 | 1.8.2-2 |
| debian | debian_linux | — | — |
| debian | tinyproxy | < tinyproxy 1.8.2-2 (bookworm) | tinyproxy 1.8.2-2 (bookworm) |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv2.6LOW
vendor_debian2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gf7c-j3g3-g2r4: acl
ghsa_unreviewed·2022-05-17
CVE-2011-1499 [LOW] GHSA-gf7c-j3g3-g2r4: acl
acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.
OSV
CVE-2011-1499: acl
osv·2011-04-29·CVSS 2.6
CVE-2011-1499 [LOW] CVE-2011-1499: acl
acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.
Debian
CVE-2011-1499: tinyproxy - acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a...
vendor_debian·2011·CVSS 2.6
CVE-2011-1499 [LOW] CVE-2011-1499: tinyproxy - acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a...
acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1499 CVE-2011-1843 tinyproxy: multiple flaws corrected in version 1.8.3 [epel-all]
bugzilla·2011-05-03·CVSS 2.6
CVE-2011-1499 [LOW] CVE-2011-1499 CVE-2011-1843 tinyproxy: multiple flaws corrected in version 1.8.3 [epel-all]
CVE-2011-1499 CVE-2011-1843 tinyproxy: multiple flaws corrected in version 1.8.3 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=694658
Please note: this issue
Bugzilla
CVE-2011-1499 CVE-2011-1843 tinyproxy: multiple flaws corrected in version 1.8.3 [fedora-all]
bugzilla·2011-05-03·CVSS 2.6
CVE-2011-1499 [LOW] CVE-2011-1499 CVE-2011-1843 tinyproxy: multiple flaws corrected in version 1.8.3 [fedora-all]
CVE-2011-1499 CVE-2011-1843 tinyproxy: multiple flaws corrected in version 1.8.3 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=694658
Please note: this iss
Bugzilla
CVE-2011-1499 CVE-2011-1843 tinyproxy: multiple flaws corrected in version 1.8.3
bugzilla·2011-04-07·CVSS 2.6
CVE-2011-1499 [LOW] CVE-2011-1499 CVE-2011-1843 tinyproxy: multiple flaws corrected in version 1.8.3
CVE-2011-1499 CVE-2011-1843 tinyproxy: multiple flaws corrected in version 1.8.3
It was reported [1] that tinyproxy prior to version 1.8.3, when configured to allow a network range (i.e. "Allow 192.168.0.0/24" versus the default "Allow 127.0.0.1"), would allow any connections from any IP address, turning it into an open proxy. If tinyproxy were configured with one or more Allow statements that use an IP range, this would occur.
This has been fixed upstream [2] and affects the versions of tinyproxy as provided by Fedora and EPEL.
[1] https://banu.com/bugzilla/show_bug.cgi?id=90
[2] https://banu.com/cgit/tinyproxy/commit/?id=e8426f6662dc467bd1d827100481b95d9a4a23e4
Discussion:
This was assigned the name CVE-2011-1499.
---
Common Vulnerabilities and Exposures assigned an identifier CVE
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=621493http://openwall.com/lists/oss-security/2011/04/07/9http://openwall.com/lists/oss-security/2011/04/08/3http://secunia.com/advisories/44274http://www.debian.org/security/2011/dsa-2222https://banu.com/bugzilla/show_bug.cgi?id=90https://banu.com/cgit/tinyproxy/diff/?id=e8426f6662dc467bd1d827100481b95d9a4a23e4https://bugzilla.redhat.com/show_bug.cgi?id=694658https://exchange.xforce.ibmcloud.com/vulnerabilities/67256http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=621493http://openwall.com/lists/oss-security/2011/04/07/9http://openwall.com/lists/oss-security/2011/04/08/3http://secunia.com/advisories/44274http://www.debian.org/security/2011/dsa-2222https://banu.com/bugzilla/show_bug.cgi?id=90https://banu.com/cgit/tinyproxy/diff/?id=e8426f6662dc467bd1d827100481b95d9a4a23e4https://bugzilla.redhat.com/show_bug.cgi?id=694658https://exchange.xforce.ibmcloud.com/vulnerabilities/67256
2011-04-29
Published