Alerts This Week
Warning Icon 1 1,220
Alerts This Week
Warning Icon 1 1,220

Ubuntu 14.04 LTS: USN-7140-2 moderate: tinyproxy sensitive data leak

ubuntu
Calendar Grey January 6, 2025
Dist Ubuntu Esm H88
Ubuntu Security Notice USN-7140-2 provides details for addressing a sensitive data leak in tinyproxy on Ubuntu 14.04 LTS.
tinyproxy could be made to expose sensitive information.

Summary

tinyproxy could be made to expose sensitive information.

Software Description:

- tinyproxy: Lightweight, non-caching, optionally anonymizing HTTP proxy

Details:

USN-7140-1 fixed CVE-2022-40468 in tinyproxy. This update provides the

corresponding update for Ubuntu 14.04 LTS.

Original advisory details:

 It was discovered that Tinyproxy did not properly manage memory under

 certain circumstances. An attacker could possibly use this issue to leak

 left-over heap data if custom error page templates containing special

 non-standard variables are used.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS
   tinyproxy                       1.8.3-3ubuntu14.04.1~esm2
                                   Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-7140-2

  https://ubuntu.com/security/notices/USN-7140-1

  CVE-2022-40468

Ubuntu Security Notice USN-7140-2

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here