This update for privoxy fixes the following issues:
Update to version 3.0.32:
- Security/Reliability (boo#1183129)
- ssplit(): Remove an assertion that could be triggered with a crafted
CGI request. Commit 2256d7b4d67. OVE-20210203-0001. CVE-2021-20272
Reported by: Joshua Rogers (Opera)
- cgi_send_banner(): Overrule invalid image types. Prevents a crash
with a crafted CGI request if Privoxy is toggled off. Commit
e711c505c48. OVE-20210206-0001. CVE-2021-20273 Reported by: Joshua
Rogers (Opera)
- socks5_connect(): Don't try to send credentials when none are
configured. Fixes a crash due to a NULL-pointer dereference when the
socks server misbehaves. Commit 85817cc55b9. OVE-20210207-0001.
CVE-2021-20274 Reported by: Joshua Rogers (Opera)
- chunked_body_is_complete(): Prevent an invalid read of size two.
Commit a912ba7bc9c. OVE-20210205-0001. CVE-2021-20275 Reported...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-443=1
- openSUSE Leap 15.2 (x86_64):
privoxy-3.0.32-lp152.3.9.1
privoxy-debuginfo-3.0.32-lp152.3.9.1
privoxy-debugsource-3.0.32-lp152.3.9.1
- openSUSE Leap 15.2 (noarch):
privoxy-doc-3.0.32-lp152.3.9.1
https://www.suse.com/security/cve/CVE-2021-20272.html
https://www.suse.com/security/cve/CVE-2021-20273.html
https://www.suse.com/security/cve/CVE-2021-20274.html
https://www.suse.com/security/cve/CVE-2021-20275.html
https://www.suse.com/security/cve/CVE-2021-20276.html
https://bugzilla.suse.com/1183129
Get the latest Linux and open source security news straight to your inbox.