{"id":"CVE-2011-1499","details":"acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.","modified":"2026-04-10T03:41:44.279167Z","published":"2011-04-29T22:55:00Z","references":[{"type":"ADVISORY","url":"http://openwall.com/lists/oss-security/2011/04/07/9"},{"type":"ADVISORY","url":"http://openwall.com/lists/oss-security/2011/04/08/3"},{"type":"ADVISORY","url":"http://secunia.com/advisories/44274"},{"type":"ADVISORY","url":"http://www.debian.org/security/2011/dsa-2222"},{"type":"ARTICLE","url":"http://openwall.com/lists/oss-security/2011/04/07/9"},{"type":"ARTICLE","url":"http://openwall.com/lists/oss-security/2011/04/08/3"},{"type":"FIX","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=621493"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=694658"},{"type":"REPORT","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=621493"},{"type":"REPORT","url":"https://banu.com/bugzilla/show_bug.cgi?id=90"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=694658"},{"type":"WEB","url":"https://banu.com/cgit/tinyproxy/diff/?id=e8426f6662dc467bd1d827100481b95d9a4a23e4"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/67256"}],"schema_version":"1.7.5"}