MGASA-2015-0003

Source
https://advisories.mageia.org/MGASA-2015-0003.html
Import Source
https://advisories.mageia.org/MGASA-2015-0003.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0003
Published
2015-01-05T16:30:30Z
Modified
2026-04-16T04:28:47Z
Summary
Updated privoxy package fixes security vulnerabilities
Details

Updated privoxy packages fix security issues:

A memory leak occurred in privoxy 3.0.21 compiled with IPv6 support when rejecting client connections due to the socket limit being reached. (CID 66382)

A use-after-free bug was found in privoxy 3.0.21 and two additional potential use-after-free issues were detected by Coverity scan. (CID 66394, CID 66376, CID 66391)

Also fixed is a file descriptor leak in an error path in jbsockets.c. (CID 66368)

References
Credits

Affected packages

Mageia:4 / privoxy

Package

Name
privoxy
Purl
pkg:rpm/mageia/privoxy?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.21-2.2.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0003.json"