openwrt ▾
›
openwrt-25.12 ▾
›
vulnerability
›
CVE-2022-40468
Component Overview
Vulnerability Overview
Name
CVE-2022-40468
Source
NVD (
link
)
Debian (
link
)
Description
Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.
CWEs
CWE-1188
Published Date
Sep 19, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/tinyproxy/tinyproxy
Third Party Advisory
https://github.com/tinyproxy/tinyproxy/blob/84f203fb1c4733608c7283bbe794005a469c4b00/src/reqs.c#L346
Exploit
https://github.com/tinyproxy/tinyproxy/issues/457
Exploit
https://github.com/tinyproxy/tinyproxy
Third Party Advisory
https://github.com/tinyproxy/tinyproxy/blob/84f203fb1c4733608c7283bbe794005a469c4b00/src/reqs.c#L346
Exploit
https://github.com/tinyproxy/tinyproxy/issues/457
Exploit
Analysis
#
Affected Component
Analysis
tinyproxy
Exploitable
Vulnerability Rating
#
7.5
CVSSv31
Others affected components
#
Name
Project
Project Version
Version
Status
tinyproxy
buildroot
2025.02.x
1.11.2
Not Affected
tinyproxy
buildroot
master
1.11.2
Not Affected
tinyproxy
openwrt
master
1.11.1-r4
Exploitable
tinyproxy
yocto
kirkstone
1.11.0
Patched
tinyproxy
yocto
master
1.11.3
Not Affected
tinyproxy
yocto
scarthgap
1.11.1
Patched
Resolved with patches
#
tinyproxy (yocto:kirkstone)
#
Title
Author
Resolve
1
prevent junk from showing up in error page in invalid
rofl0r <rofl0r@users.noreply.github.com>
CVE-2022-40468
tinyproxy (yocto:scarthgap)
#
Title
Author
Resolve
1
prevent junk from showing up in error page in invalid
rofl0r <rofl0r@users.noreply.github.com>
CVE-2022-40468