Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3r7-x4mp-2c39

Опубликовано: 20 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Tinyproxy commit 84f203f and earlier does not process HTTP request lines in the process_request() function and is using uninitialized buffers. This vulnerability allows attackers to access sensitive information at system runtime.

Tinyproxy commit 84f203f and earlier does not process HTTP request lines in the process_request() function and is using uninitialized buffers. This vulnerability allows attackers to access sensitive information at system runtime.

EPSS

Процентиль: 33%
0.00132
Низкий

7.5 High

CVSS3

Дефекты

CWE-1188

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.

CVSS3: 7.5
nvd
больше 3 лет назад

Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.

CVSS3: 7.5
debian
больше 3 лет назад

Potential leak of left-over heap data if custom error page templates c ...

suse-cvrf
больше 1 года назад

Security update for tinyproxy

EPSS

Процентиль: 33%
0.00132
Низкий

7.5 High

CVSS3

Дефекты

CWE-1188