Summary
The remote host is missing an update to tinyproxy
announced via advisory DSA 2222-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202222-1
Insight
Christoph Martin discovered that incorrect ACL processing in TinyProxy, a lightweight, non-caching, optionally anonymizing http proxy could lead to unintended network access rights.
The oldstable distribution (lenny) is not affected.
For the stable distribution (squeeze), this problem has been fixed in version 1.8.2-1squeeze1.
For the unstable distribution (sid), this problem has been fixed in version 1.8.2-2
We recommend that you upgrade your tinyproxy packages.
Severity
Classification
-
CVE CVE-2011-1499 -
CVSS Base Score: 2.6
AV:N/AC:H/Au:N/C:N/I:P/A:N
Related Vulnerabilities