CVE-2021-20210: High severity privoxy vulnerability
A flaw was found in Privoxy in versions before 3.0.29. Memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash.
Other sources
Memory leak in the show-status CGI handler when no filter files are configured
Upstream Patch: https://www.privoxy.org/gitweb/?p=privoxy.git;a=commit;h=1b1370f7a8a
External References:
https://www.privoxy.org/3.0.29/user-manual/whatsnew.html
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Privoxy flaw?
The vulnerability ID for this Privoxy flaw is CVE-2021-20210.
What is the severity of CVE-2021-20210?
The severity of CVE-2021-20210 is high with a severity score of 7.5.
What is the affected software for CVE-2021-20210?
The affected software for CVE-2021-20210 is Privoxy versions before 3.0.29.
How can this vulnerability lead to a system crash?
The memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash.
How can I fix CVE-2021-20210?
To fix CVE-2021-20210, update Privoxy to version 3.0.29 or later.