← Back

CVE-2011-1499

nvd nist
Published: Apr 29, 2011Modified: Apr 29, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:N/I:P/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.

Affected (52)

1 product
Tinyproxy
1 product
Debian Linux
Configuration A
51 vulnerable
Vulnerable SoftwareAffected Versions
Banu
Up to 1.8.2
Version 1.5.0
Version 1.5.0 pre1
Version 1.5.0 pre2
Version 1.5.0 pre3
Version 1.5.0 pre4
Version 1.5.0 pre5
Version 1.5.0 pre6
Version 1.5.0 rc10
Version 1.5.0 rc1
Version 1.5.0 rc2
Version 1.5.0 rc4
Version 1.5.0 rc5
Version 1.5.0 rc6
Version 1.5.0 rc7
Version 1.5.0 rc8
Version 1.5.0 rc9
Version 1.5.1
Version 1.5.1 pre1
Version 1.5.1 pre2
Version 1.5.1 pre3
Version 1.5.1 pre4
Version 1.5.1 pre5
Version 1.5.1 pre6
Version 1.5.1 rc1
Version 1.5.1 rc2
Version 1.5.1 rc3
Version 1.5.1 rc4
Version 1.5.2
Version 1.5.2 rc1
Version 1.5.2 rc2
Version 1.5.3
Version 1.5.3 rc1
Version 1.6.0
Version 1.6.0 a
Version 1.6.0 pre1
Version 1.6.0 pre2
Version 1.6.0 pre3
Version 1.6.0 pre4
Version 1.6.0 rc1
Version 1.6.0 rc2
Version 1.6.0 rc3
Version 1.6.1
Version 1.6.2
Version 1.6.3
Version 1.6.4
Version 1.6.5
Version 1.7.0
Version 1.7.1
Version 1.8.0
Version 1.8.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.0

Related CWEs

References (18)

Source: secalert@redhat.com
Issue TrackingPatch
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.