Debian Security Advisory
DSA-2222-1 tinyproxy -- incorrect ACL processing
- Date Reported:
- 20 Apr 2011
- Affected Packages:
- tinyproxy
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 621493.
In Mitre's CVE dictionary: CVE-2011-1499. - More information:
-
Christoph Martin discovered that incorrect ACL processing in TinyProxy, a lightweight, non-caching, optionally anonymizing HTTP proxy, could lead to unintended network access rights.
The oldstable distribution (lenny) is not affected.
For the stable distribution (squeeze), this problem has been fixed in version 1.8.2-1squeeze1.
For the unstable distribution (sid), this problem has been fixed in version 1.8.2-2.
We recommend that you upgrade your tinyproxy packages.