Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qc4p-7g72-jqrq

Опубликовано: 01 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

An uninitialized memory use vulnerability exists in Tinyproxy 1.11.1 while parsing HTTP requests. In certain configurations, a specially crafted HTTP request can result in disclosure of data allocated on the heap, which could contain sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

An uninitialized memory use vulnerability exists in Tinyproxy 1.11.1 while parsing HTTP requests. In certain configurations, a specially crafted HTTP request can result in disclosure of data allocated on the heap, which could contain sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

5.9 Medium

CVSS3

Дефекты

CWE-457

Связанные уязвимости

ubuntu
почти 2 года назад

Rejected reason: This CVE ID is a duplicate of CVE-2022-40468

nvd
почти 2 года назад

Rejected reason: This CVE ID is a duplicate of CVE-2022-40468

suse-cvrf
больше 1 года назад

Security update for tinyproxy

5.9 Medium

CVSS3

Дефекты

CWE-457