PT-2021-27317 · Privoxy · Privoxy

Published

2021-01-04

·

Updated

2021-01-04

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: privoxy versions prior to 3.0.29
Description: The issue is related to memory leaks in the privoxy software. Specifically, memory leaks occur when a response is buffered and the buffer limit is reached or privoxy is running out of memory. Additionally, there are memory leaks in the show-status CGI handler when no action files or filter files are configured. The issue also involves an unlikely dereference of a NULL-pointer that could result in a crash if accept-intercepted-requests is enabled and Privoxy fails to get the request destination from the Host header and a memory allocation fails.
Recommendations: Update to version 3.0.29 to fix the memory leaks and other issues. As a temporary workaround, consider disabling the CGI handlers or restricting the use of the affected features until the update is applied.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

OPENSUSE-SU-2021:0016-1

Affected Products

Privoxy