High severity7.5NVD Advisory· Published Sep 19, 2022· Updated Jun 17, 2026
CVE-2022-40468
CVE-2022-40468
Description
Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords3 versionspkg:rpm/opensuse/tinyproxy&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/tinyproxy&distro=openSUSE%20Tumbleweedpkg:rpm/suse/tinyproxy&distro=SUSE%20Package%20Hub%2015%20SP5
< 1.11.2-bp155.3.3.1+ 2 more
- (no CPE)range: < 1.11.2-bp155.3.3.1
- (no CPE)range: < 1.11.1-2.1
- (no CPE)range: < 1.11.2-bp155.3.3.1
Patches
Vulnerability mechanics
References
5- github.com/tinyproxy/tinyproxy/blob/84f203fb1c4733608c7283bbe794005a469c4b00/src/reqs.cnvdExploitThird Party Advisory
- github.com/tinyproxy/tinyproxy/issues/457nvdExploitThird Party Advisory
- github.com/tinyproxy/tinyproxy/issues/457nvd
- lists.debian.org/debian-lts-announce/2024/09/msg00035.htmlnvd
- security.gentoo.org/glsa/202305-27nvd
News mentions
0No linked articles in our index yet.