MGASA-2021-0089 - Updated privoxy package fixes security vulnerabilities Publication date: 19 Feb 2021 URL: https://advisories.mageia.org/MGASA-2021-0089.html Type: security Affected Mageia releases: 7 CVE: CVE-2021-20216, CVE-2021-20217 Fixed a memory leak when decompression fails "unexpectedly". (CVE-2021-20216) Prevent an assertion from getting triggered by a crafted CGI request. (CVE-2021-20217) References: - https://bugs.mageia.org/show_bug.cgi?id=28281 - https://www.privoxy.org/announce.txt - https://www.openwall.com/lists/oss-security/2021/02/04/4 - https://lists.opensuse.org/archives/list/[email protected]/thread/LYXYETZZHYGLBE3WLXSZCYBO5VDRKFDT/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20216 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20217 SRPMS: - 7/core/privoxy-3.0.31-1.mga7