CVE-2017-11747 affects Tinyproxy versions 1.8.4 and earlier, where a race condition allows a local, low-privileged attacker to kill arbitrary processes. The vulnerability arises because Tinyproxy creates its PID file after dropping root privileges, enabling an attacker with access to the non-root Tinyproxy account to modify the PID file before a root script attempts to kill the process ID specified within. This is a medium severity vulnerability (CVSS 5.5) with low attack complexity, requiring local access and user interaction to achieve high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8.4CPE matchmatch criteria | cpe:2.3:a:tinyproxy_project:tinyproxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.