Information on source package tinyproxy

Available versions

ReleaseVersion
jessie1.8.3-3+deb8u1
stretch1.8.4-3~deb9u2
buster1.10.0-2+deb10u1
bullseye1.10.0-5
bullseye (security)1.10.0-5+deb11u1
bookworm1.11.1-2.1+deb12u1
trixie1.11.2-1
sid1.11.2-1

Open issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2023-49606vulnerablevulnerablevulnerable (no DSA, postponed)fixedfixedfixedfixedA use-after-free vulnerability exists in the HTTP Connection Headers p ...
CVE-2023-40533vulnerablevulnerableunknownunknownunknownunknownunknown
CVE-2022-40468vulnerablefixedvulnerable (no DSA, postponed)fixedfixedfixedfixedPotential leak of left-over heap data if custom error page templates c ...

Resolved issues

BugDescription
CVE-2017-11747main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinypro ...
CVE-2012-3505Tinyproxy 1.8.3 and earlier allows remote attackers to cause a denial ...
CVE-2011-1843Integer overflow in conf.c in Tinyproxy before 1.8.3 might allow remot ...
CVE-2011-1499acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting s ...
CVE-2002-0847tinyproxy HTTP proxy 1.5.0, 1.4.3, and earlier allows remote attackers ...

Security announcements

DSA / DLADescription
DLA-3892-1tinyproxy - security update
DSA-5705-1tinyproxy - security update
DLA-2163-1tinyproxy - security update
DSA-2564-1tinyproxy - denial of service
DSA-2222-1tinyproxy - incorrect ACL processing
DSA-145tinyproxy - doubly freed memory

Search for package or bug name: Reporting problems