Debian Security Advisory

DSA-2222-1 tinyproxy -- incorrect ACL processing

Date Reported:
20 Apr 2011
Affected Packages:
tinyproxy
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 621493.
In Mitre's CVE dictionary: CVE-2011-1499.
More information:

Christoph Martin discovered that incorrect ACL processing in TinyProxy, a lightweight, non-caching, optionally anonymizing HTTP proxy, could lead to unintended network access rights.

The oldstable distribution (lenny) is not affected.

For the stable distribution (squeeze), this problem has been fixed in version 1.8.2-1squeeze1.

For the unstable distribution (sid), this problem has been fixed in version 1.8.2-2.

We recommend that you upgrade your tinyproxy packages.