Integer overflow in conf.c in Tinyproxy before 1.8.3 might allow remote attackers to bypass intended access restrictions in opportunistic circumstances via a TCP connection, related to improper handling of invalid port numbers.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
https://banu.com/cgit/tinyproxy/diff/?id=97b9984484299b2ce72f8f4fc3706dab8a3a8439 | patch |
http://www.securityfocus.com/bid/47715 | vdb entry |
https://banu.com/bugzilla/show_bug.cgi?id=90 | patch exploit |