CVE-2015-1382: Input Validation
Published Feb 3, 2015
·Updated
parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.
Affected Software
4 affected components
Debian Debian Linux=7.0
Privoxy privoxy<=3.0.22
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Event History
Feb 3, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1382?
CVE-2015-1382 has a medium severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2015-1382?
To fix CVE-2015-1382, upgrade to Privoxy version 3.0.23 or later.
3
Which versions of Privoxy are affected by CVE-2015-1382?
Privoxy versions prior to 3.0.23 are affected by CVE-2015-1382.
4
What is the impact of CVE-2015-1382?
CVE-2015-1382 can lead to an invalid read and crashing of the application when processing an HTTP time header.
5
Are Debian and openSUSE affected by CVE-2015-1382?
Yes, Debian 7.0 and openSUSE versions 13.1 and 13.2 are affected by CVE-2015-1382.