CVE-2015-1380: Input Validation
Published Feb 3, 2015
·Updated
jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
Affected Software
4 affected components
Privoxy privoxy<=3.0.22
Oracle Solaris=11.2
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Event History
Feb 3, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1380?
CVE-2015-1380 has a severity rating that qualifies it as a denial of service vulnerability.
2
How can I fix CVE-2015-1380?
To fix CVE-2015-1380, upgrade Privoxy to version 3.0.23 or later.
3
Which software is affected by CVE-2015-1380?
CVE-2015-1380 affects Privoxy versions before 3.0.23, and specific versions of Oracle Solaris and openSUSE.
4
What type of attack is associated with CVE-2015-1380?
CVE-2015-1380 allows remote attackers to cause a denial of service through crafted chunk-encoded bodies.
5
Is there a workaround for CVE-2015-1380?
Currently, the recommended action is to upgrade to a secure version as there are no specific workarounds.