CVE-2021-20214: High severity privoxy vulnerability
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system crash.
Other sources
Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail
Upstream Patch:
https://www.privoxy.org/gitweb/?p=privoxy.git;a=commit;h=cf5640eb2a
External References:
https://www.privoxy.org/3.0.29/user-manual/whatsnew.html
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20214?
CVE-2021-20214 is a vulnerability found in Privoxy versions before 3.0.29 that can lead to a system crash due to memory leaks in the client-tags CGI handler.
How severe is CVE-2021-20214?
CVE-2021-20214 has a severity rating of 7.5 (high).
How can I fix CVE-2021-20214?
To fix CVE-2021-20214, you should update Privoxy to version 3.0.29.
Where can I find more information about CVE-2021-20214?
You can find more information about CVE-2021-20214 at the following references: [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi?id=1928742), [Gentoo GLSA](https://security.gentoo.org/glsa/202107-16), [Privoxy User Manual](https://www.privoxy.org/3.0.29/user-manual/whatsnew.html).
What is the common weakness enumeration (CWE) ID for CVE-2021-20214?
The CWE ID for CVE-2021-20214 is CWE-401.