CVE-2012-3505
published 2012-10-09CVE-2012-3505: Tinyproxy 1.8.3 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via (1) a large number of headers or (2) a large…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
7.35%
93.8th percentile
Tinyproxy 1.8.3 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via (1) a large number of headers or (2) a large number of forged headers that trigger hash collisions predictably. bucket.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| banu | tinyproxy | <= 1.8.3 | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | — | — |
| banu | tinyproxy | >= 0 < 1.8.3-3 | 1.8.3-3 |
| banu | tinyproxy | >= 0 < 1.8.3-3 | 1.8.3-3 |
| banu | tinyproxy | >= 0 < 1.8.3-3 | 1.8.3-3 |
| banu | tinyproxy | >= 0 < 1.8.3-3 | 1.8.3-3 |
| debian | tinyproxy | < tinyproxy 1.8.3-3 (bookworm) | tinyproxy 1.8.3-3 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h6wx-vrmp-rrjr: Tinyproxy 1
ghsa_unreviewed·2022-05-17
CVE-2012-3505 [MEDIUM] GHSA-h6wx-vrmp-rrjr: Tinyproxy 1
Tinyproxy 1.8.3 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via (1) a large number of headers or (2) a large number of forged headers that trigger hash collisions predictably. bucket.
OSV
CVE-2012-3505: Tinyproxy 1
osv·2012-10-09·CVSS 5.0
CVE-2012-3505 [MEDIUM] CVE-2012-3505: Tinyproxy 1
Tinyproxy 1.8.3 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via (1) a large number of headers or (2) a large number of forged headers that trigger hash collisions predictably. bucket.
Debian
CVE-2012-3505: tinyproxy - Tinyproxy 1.8.3 and earlier allows remote attackers to cause a denial of service...
vendor_debian·2012·CVSS 5.0
CVE-2012-3505 [MEDIUM] CVE-2012-3505: tinyproxy - Tinyproxy 1.8.3 and earlier allows remote attackers to cause a denial of service...
Tinyproxy 1.8.3 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via (1) a large number of headers or (2) a large number of forged headers that trigger hash collisions predictably. bucket.
Scope: local
bookworm: resolved (fixed in 1.8.3-3)
bullseye: resolved (fixed in 1.8.3-3)
forky: resolved (fixed in 1.8.3-3)
sid: resolved (fixed in 1.8.3-3)
trixie: resolved (fixed in 1.8.3-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3505 tinyproxy: multiple headers hashmap DoS
bugzilla·2012-08-18·CVSS 5.0
CVE-2012-3505 [MEDIUM] CVE-2012-3505 tinyproxy: multiple headers hashmap DoS
CVE-2012-3505 tinyproxy: multiple headers hashmap DoS
gpernot reports:
Bug 110 - algorithmic complexity denial of service
randomized hashmaps to prevent DOS attacks
hashmap are not randomized, so that it is possible to forge fake headers that
will always go into the same bucket.
try 'curl http://78.230.4.96/hashes.asis' via tinyproxy and without it to
convince you (~8 MB of headers). I'll remove this url as soon as bug is
accepted...
attached patch should solve this. it's certainly perfectible, though
(autoconf for time() and rand() are missing...).
even with this patch, it takes ages. maybe headers should be sanitized before
hiting the buckets...
Created attachment 60 [details]
limit number of headers to prevent DoS attacks
External references:
https://banu.com/bugzilla/show_bug.c
Bugzilla
CVE-2012-3505 tinyproxy: multiple headers hashmap DoS [epel-all]
bugzilla·2012-08-18·CVSS 5.0
CVE-2012-3505 [MEDIUM] CVE-2012-3505 tinyproxy: multiple headers hashmap DoS [epel-all]
CVE-2012-3505 tinyproxy: multiple headers hashmap DoS [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=84936
Bugzilla
CVE-2012-3505 tinyproxy: multiple headers hashmap DoS [fedora-all]
bugzilla·2012-08-18·CVSS 5.0
CVE-2012-3505 [MEDIUM] CVE-2012-3505 tinyproxy: multiple headers hashmap DoS [fedora-all]
CVE-2012-3505 tinyproxy: multiple headers hashmap DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=849
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=685281http://secunia.com/advisories/50278http://secunia.com/advisories/51074http://www.debian.org/security/2012/dsa-2564http://www.openwall.com/lists/oss-security/2012/08/17/3http://www.openwall.com/lists/oss-security/2012/08/18/1http://www.securitytracker.com/id?1027412https://banu.com/bugzilla/show_bug.cgi?id=110https://banu.com/bugzilla/show_bug.cgi?id=110#c2https://bugs.launchpad.net/ubuntu/+source/tinyproxy/+bug/1036985http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=685281http://secunia.com/advisories/50278http://secunia.com/advisories/51074http://www.debian.org/security/2012/dsa-2564http://www.openwall.com/lists/oss-security/2012/08/17/3http://www.openwall.com/lists/oss-security/2012/08/18/1http://www.securitytracker.com/id?1027412https://banu.com/bugzilla/show_bug.cgi?id=110https://banu.com/bugzilla/show_bug.cgi?id=110#c2https://bugs.launchpad.net/ubuntu/+source/tinyproxy/+bug/1036985
2012-10-09
Published