Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Mageia 8 MGASA-2021-0570 Moderate: Privoxy Memory Leak Risk

mageia
Calendar Grey December 19, 2021
Dist Mageia Esm H88
The recent maintenance patch for privoxy corrects memory leaks and mitigates cross-origin scripting vulnerabilities to bolster overall system security.
Updated privoxy packages fix security vulnerabilities: A security issue has been found in Privoxy before version 3.0.33

Summary

Updated privoxy packages fix security vulnerabilities:
A security issue has been found in Privoxy before version 3.0.33. get_url_spec_param() did not free memory of compiled pattern spec before bailing (CVE-2021-44540).
A security issue has been found in Privoxy before version 3.0.33. process_encrypted_request_headers() did not free header memory when failing to get the request destination (CVE-2021-44541).
A security issue has been found in Privoxy before version 3.0.33. send_http_request() leaked memory when handling errors (CVE-2021-44542).
A security issue has been found in Privoxy before version 3.0.33. cgi_error_no_template() did not encode the template name, which could lead to cross-site scripting when Privoxy is configured to servce the user-manual itself (CVE-2021-44543).

References

- https://bugs.mageia.org/show_bug.cgi?id=29745

- http://www.privoxy.org/announce.txt

- https://www.cve.org/CVERecord?id=CVE-2021-44540

- https://www.cve.org/CVERecord?id=CVE-2021-44541

- https://www.cve.org/CVERecord?id=CVE-2021-44542

- https://www.cve.org/CVERecord?id=CVE-2021-44543

Resolution

SRPMS

- 8/core/privoxy-3.0.32-1.1.mga8

Publication date: 19 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0570.html
Type: security
CVE: CVE-2021-44540, CVE-2021-44541, CVE-2021-44542, CVE-2021-44543

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here