Tinyproxy: Memory Disclosure A vulnerability has been discovered in Tinyproxy which could be used to achieve memory disclosure. tinyproxy 2023-05-21 2023-05-21 871924 remote 1.11.1_p20220908 1.11.1_p20220908

Tinyproxy is a light-weight HTTP/HTTPS proxy daemon for POSIX operating systems.

Tinyproxy's request processing does not sufficiently null-initialize variables used in error pages.

Contents of the Tinyproxy server's memory could be disclosed via generated error pages.

There is no known workaround at this time.

All Tinyproxy users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-proxy/tinyproxy-1.11.1_p20220908"
CVE-2022-40468 ajak ajak