CVE-2017-11747
N/A
N/A
Summary
main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tinyproxy.pid modification before a root script executes a "kill cat /run/tinyproxy/tinyproxy.pid" command.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://github.com/tinyproxy/tinyproxy/issues/106
- https://lists.debian.org/debian-lts-announce/2020/03/msg00037.html
References
- https://github.com/tinyproxy/tinyproxy/issues/106
- https://lists.debian.org/debian-lts-announce/2020/03/msg00037.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.