7.5
CVSSv3

CVE-2022-40468

Published: 19/09/2022 Updated: 21/05/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and previous versions use uninitialized buffers in process_request() function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tinyproxy project tinyproxy

Vendor Advisories

Debian Bug report logs - #1021015 tinyproxy: CVE-2022-40468 Package: src:tinyproxy; Maintainer for src:tinyproxy is Mike Gabriel <sunweaver@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 30 Sep 2022 14:51:02 UTC Severity: important Tags: security, upstream Found in version tinyproxy/1111- ...