10
CVSSv2

CVE-2001-0129

Published: 12/03/2001 Updated: 03/05/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and previous versions allows remote malicious users to cause a denial of service and possibly execute arbitrary commands via a long connect request.

Vulnerable Product Search on Vulmon Subscribe to Product

tinyproxy tinyproxy 1.3.3

tinyproxy tinyproxy

Vendor Advisories

PkC have found a heap overflow in tinyproxy that could be remotely exploited An attacker could gain a shell (user nobody) remotely We recommend you upgrade your tinyproxy package immediately ...

Exploits

source: wwwsecurityfocuscom/bid/2217/info Versions 132 and 133 of tinyproxy, a small HTTP proxy, exhibit a vulnerability to heap overflow attacks A failure to properly validate user-supplied input which arguments a call to sprintf() can allow unexpectedly large amounts of input to a buffer (used to display error messages) to be writ ...