PT-2021-27318 · Privoxy · Privoxy
Published
2021-01-04
·
Updated
2021-01-04
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
privoxy versions prior to 3.0.29
Description:
The issue is related to memory leaks in the privoxy software. Specifically, memory leaks occur when a response is buffered and the buffer limit is reached or privoxy is running out of memory. Additionally, there are memory leaks in the show-status CGI handler when no action files or filter files are configured. The issue also involves an unlikely dereference of a NULL-pointer that could result in a crash if accept-intercepted-requests was enabled and certain conditions are met.
Recommendations:
Update to version 3.0.29 or later to fix the memory leaks and other issues. As a temporary workaround, consider disabling the CGI handlers or restricting their use until the update is applied.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Privoxy