Over 50,000 Tinyproxy servers vulnerable to critical RCE flaw
ID: 278b0fc1-2a21-503c-aff5-84e477adc36e
STIX ID: report--278b0fc1-2a21-503c-aff5-84e477adc36e
Feed Name: Bleeping Computer
Threat Score
**Tinyproxy CVE-2023-49606:** A critical use-after-free vulnerability in Tinyproxy (affecting versions 1.10.0 and 1.11.1) can be exploited via crafted HTTP Connection headers to crash servers and potentially achieve remote code execution; Talos published PoC exploits and Censys found a large number of internet-exposed instances that appear vulnerable, and maintainers released a patch in the master branch to address the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
