First published: Wed Jan 27 2016(Updated: )
The remove_chunked_transfer_coding function in filters.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via crafted chunk-encoded content.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Privoxy | <=3.0.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1982 has a severity rating of medium due to its potential to cause denial of service.
To fix CVE-2016-1982, upgrade Privoxy to version 3.0.24 or later.
CVE-2016-1982 exploits a flaw in the remove_chunked_transfer_coding function allowing for invalid reads.
Yes, CVE-2016-1982 can be exploited remotely through crafted chunk-encoded content.
CVE-2016-1982 affects Privoxy versions up to and including 3.0.23.