CVE-2021-20209: High severity privoxy vulnerability
A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured.
Other sources
Memory leak in the show-status CGI handler when no action files are configured.
Upstream Patch:
https://www.privoxy.org/gitweb/?p=privoxy.git;a=commit;h=c62254a686
External References:
https://www.privoxy.org/3.0.29/user-manual/whatsnew.html
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this memory leak vulnerability?
The vulnerability ID for this memory leak vulnerability is CVE-2021-20209.
What is the severity level of CVE-2021-20209?
The severity level of CVE-2021-20209 is high with a CVSS score of 7.5.
Which software is affected by CVE-2021-20209?
Privoxy versions before 3.0.29 are affected by CVE-2021-20209.
How can I fix the memory leak vulnerability in Privoxy?
To fix the memory leak vulnerability in Privoxy, upgrade to version 3.0.29 or higher.
Where can I find more information about CVE-2021-20209?
You can find more information about CVE-2021-20209 at the following references: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1928726), [Gentoo Security](https://security.gentoo.org/glsa/202107-16), [Privoxy User Manual](https://www.privoxy.org/3.0.29/user-manual/whatsnew.html).