MGASA-2021-0570

Source
https://advisories.mageia.org/MGASA-2021-0570.html
Import Source
https://advisories.mageia.org/MGASA-2021-0570.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0570
Upstream
Published
2021-12-19T16:13:42Z
Modified
2026-04-16T04:43:53Z
Summary
Updated privoxy packages fix security vulnerabilities
Details

Updated privoxy packages fix security vulnerabilities:

A security issue has been found in Privoxy before version 3.0.33. get_url_spec_param() did not free memory of compiled pattern spec before bailing (CVE-2021-44540).

A security issue has been found in Privoxy before version 3.0.33. process_encrypted_request_headers() did not free header memory when failing to get the request destination (CVE-2021-44541).

A security issue has been found in Privoxy before version 3.0.33. send_http_request() leaked memory when handling errors (CVE-2021-44542).

A security issue has been found in Privoxy before version 3.0.33. cgi_error_no_template() did not encode the template name, which could lead to cross-site scripting when Privoxy is configured to servce the user-manual itself (CVE-2021-44543).

References
Credits

Affected packages

Mageia:8 / privoxy

Package

Name
privoxy
Purl
pkg:rpm/mageia/privoxy?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.32-1.1.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0570.json"