Critical Security Update for tinyproxy in Fedora 39 addressing CVE-2023-49606
Summary
tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a
small network setting, where a larger proxy like Squid would either be too
resource intensive, or a security risk.
Update Information:
Backport upstream patch for CVE-2023-49606.
Change Log
* Wed Jul 17 2024 Carl George
References
[ 1 ] Bug #2278396 - CVE-2023-49606 tinyproxy: HTTP connection headers use-after-free vulnerability [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2278396
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-661a8bb3b0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label