CVE-2016-1982: Input Validation
Published Jan 27, 2016
·Updated
The removechunkedtransfercoding function in filters.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via crafted chunk-encoded content.
Affected Software
1 affected component
Privoxy privoxy<=3.0.23
Event History
Jan 27, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1982?
CVE-2016-1982 has a severity rating of medium due to its potential to cause denial of service.
2
How do I fix CVE-2016-1982?
To fix CVE-2016-1982, upgrade Privoxy to version 3.0.24 or later.
3
What vulnerabilities does CVE-2016-1982 exploit?
CVE-2016-1982 exploits a flaw in the remove_chunked_transfer_coding function allowing for invalid reads.
4
Can CVE-2016-1982 be exploited remotely?
Yes, CVE-2016-1982 can be exploited remotely through crafted chunk-encoded content.
5
Which versions of Privoxy are affected by CVE-2016-1982?
CVE-2016-1982 affects Privoxy versions up to and including 3.0.23.