UbuntuUpdates.org

Package "tinyproxy-bin"

Name: tinyproxy-bin

Description:

Lightweight, non-caching, optionally anonymizing HTTP proxy (executable only)

Latest version: 1.11.1-3ubuntu0.1
Release: noble (24.04)
Level: updates
Repository: universe
Head package: tinyproxy
Homepage: https://tinyproxy.github.io/

Links


Download "tinyproxy-bin"


Other versions of "tinyproxy-bin" in Noble

Repository Area Version
base universe 1.11.1-3
security universe 1.11.1-3ubuntu0.1

Changelog

Version: 1.11.1-3ubuntu0.1 2025-01-08 13:06:58 UTC

  tinyproxy (1.11.1-3ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: use-after-free in header handling [(LP: #2074351)]
    - debian/patches/CVE-2023-49606.patch: add validation on `reqs.c` which
      ensures that the value of header is not equal to either "connection"
      or "proxy-connection" to prevent double-free
    - CVE-2023-49606

 -- Shishir Subedi <email address hidden> Fri, 13 Dec 2024 14:53:39 +0545

2074351 CVE-2023-49606
CVE-2023-49606 A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP heade



About   -   Send Feedback to @ubuntu_updates