Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 871924 (CVE-2022-40468) - <net-proxy/tinyproxy-1.11.1_p20220908: use of unintialized memory
Summary: <net-proxy/tinyproxy-1.11.1_p20220908: use of unintialized memory
Status: RESOLVED FIXED
Alias: CVE-2022-40468
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/tinyproxy/tinyprox...
Whiteboard: B4 [glsa+]
Keywords:
Depends on: 873073
Blocks:
  Show dependency tree
 
Reported: 2022-09-19 19:34 UTC by John Helmert III
Modified: 2023-05-21 19:53 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-19 19:34:33 UTC
CVE-2022-40468:

Tinyproxy commit 84f203f and earlier does not process HTTP request lines in the process_request() function and is using uninitialized buffers. This vulnerability allows attackers to access sensitive information at system runtime.

Unreleased fix is: https://github.com/tinyproxy/tinyproxy/commit/3764b8551463b900b5b4e3ec0cd9bb9182191cb7
Comment 1 Ben Kohler gentoo-dev 2022-09-20 12:03:51 UTC
commit 0aaa953b3e08b8d320e85c417faf9110bd4a120f
Author: Ben Kohler <bkohler@gentoo.org>
Date:   Tue Sep 20 07:01:51 2022 -0500

    net-proxy/tinyproxy: add 1.11.1_p20220908

    https://bugs.gentoo.org/871924

    Signed-off-by: Ben Kohler <bkohler@gentoo.org>
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-26 15:50:24 UTC
Thanks, sorry I missed this! Please stabilize when ready.
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-27 16:22:09 UTC
Please cleanup
Comment 4 Larry the Git Cow gentoo-dev 2022-09-27 16:30:07 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=66f12d93c2c7a5907c75f2ffc9313a5201e013a3

commit 66f12d93c2c7a5907c75f2ffc9313a5201e013a3
Author:     Ben Kohler <bkohler@gentoo.org>
AuthorDate: 2022-09-27 16:29:25 +0000
Commit:     Ben Kohler <bkohler@gentoo.org>
CommitDate: 2022-09-27 16:29:45 +0000

    net-misc/connman: drop 1.42_pre20220801, 1.42_pre20220828
    
    Bug: https://bugs.gentoo.org/871924
    
    Signed-off-by: Ben Kohler <bkohler@gentoo.org>

 net-misc/connman/Manifest                        |   1 -
 net-misc/connman/connman-1.42_pre20220801.ebuild | 106 -----------------------
 net-misc/connman/connman-1.42_pre20220828.ebuild | 106 -----------------------
 3 files changed, 213 deletions(-)
Comment 5 Larry the Git Cow gentoo-dev 2022-09-27 16:43:04 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d8f812cd6694204fb437994cd3a90160db34fc25

commit d8f812cd6694204fb437994cd3a90160db34fc25
Author:     Ben Kohler <bkohler@gentoo.org>
AuthorDate: 2022-09-27 16:42:21 +0000
Commit:     Ben Kohler <bkohler@gentoo.org>
CommitDate: 2022-09-27 16:42:28 +0000

    net-proxy/tinyproxy: drop 1.11.1
    
    Bug: https://bugs.gentoo.org/871924
    
    Signed-off-by: Ben Kohler <bkohler@gentoo.org>

 net-proxy/tinyproxy/Manifest                |  1 -
 net-proxy/tinyproxy/tinyproxy-1.11.1.ebuild | 76 -----------------------------
 2 files changed, 77 deletions(-)
Comment 6 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-27 17:02:58 UTC
Thanks!
Comment 7 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-10-22 01:39:08 UTC
GLSA request filed.
Comment 8 Larry the Git Cow gentoo-dev 2023-05-21 19:52:11 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=5fa49c75f6bb7e3ca649afb5387491e4e7315dbd

commit 5fa49c75f6bb7e3ca649afb5387491e4e7315dbd
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-05-21 19:44:29 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2023-05-21 19:51:36 +0000

    [ GLSA 202305-27 ] Tinyproxy: Memory Disclosure
    
    Bug: https://bugs.gentoo.org/871924
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 glsa-202305-27.xml | 42 ++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 42 insertions(+)
Comment 9 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-05-21 19:53:01 UTC
GLSA released, all done!