Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE Leap 15.2: 2021-0443-1 Moderate: Privoxy Security Update

opensuse
Calendar Grey March 18, 2021
Dist Opensuse Esm H88
A new openSUSE update is now live, addressing five major security flaws in privoxy. This improvement enhances system stability and reduces crash risks, promoting a safer user experience
An update that fixes 5 vulnerabilities is now available

Description

This update for privoxy fixes the following issues:

Update to version 3.0.32:

- Security/Reliability (boo#1183129)

- ssplit(): Remove an assertion that could be triggered with a crafted

CGI request. Commit 2256d7b4d67. OVE-20210203-0001. CVE-2021-20272

Reported by: Joshua Rogers (Opera)

- cgi_send_banner(): Overrule invalid image types. Prevents a crash

with a crafted CGI request if Privoxy is toggled off. Commit

e711c505c48. OVE-20210206-0001. CVE-2021-20273 Reported by: Joshua

Rogers (Opera)

- socks5_connect(): Don't try to send credentials when none are

configured. Fixes a crash due to a NULL-pointer dereference when the

socks server misbehaves. Commit 85817cc55b9. OVE-20210207-0001.

CVE-2021-20274 Reported by: Joshua Rogers (Opera)

- chunked_body_is_complete(): Prevent an invalid read of size two.

Commit a912ba7bc9c. OVE-20210205-0001. CVE-2021-20275 Reported...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-443=1

Package List

- openSUSE Leap 15.2 (x86_64):

privoxy-3.0.32-lp152.3.9.1

privoxy-debuginfo-3.0.32-lp152.3.9.1

privoxy-debugsource-3.0.32-lp152.3.9.1

- openSUSE Leap 15.2 (noarch):

privoxy-doc-3.0.32-lp152.3.9.1

References

https://www.suse.com/security/cve/CVE-2021-20272.html

https://www.suse.com/security/cve/CVE-2021-20273.html

https://www.suse.com/security/cve/CVE-2021-20274.html

https://www.suse.com/security/cve/CVE-2021-20275.html

https://www.suse.com/security/cve/CVE-2021-20276.html

https://bugzilla.suse.com/1183129

Announcement ID: openSUSE-SU-2021:0443-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here