It has been discovered that over half of the 90,310 hosts are using a Tinyproxy service that is online and susceptible to a serious security vulnerability in the HTTP/HTTPS proxy utility that is not yet patched.
The problem, identified as CVE-2023-49606, has a CVSS score of 9.8 out of 10, according to Cisco Talos. The company stated that the vulnerability affects versions 1.10.0 and 1.11.1, which is the most recent version.
According to a Talos report last week, a specifically constructed HTTP header can cause memory corruption and remote code execution by reusing previously freed memory. This vulnerability requires an unauthenticated HTTP request to be made by an attacker.
Stated differently, memory corruption that might lead to remote code execution read more Critical Tinyproxy Flaw Opens Over 50000 Hosts to Remote Code Execution.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
