CVE-2021-20215: High severity privoxy vulnerability
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.
Other sources
Memory leaks in the show-status CGI handler when memory allocations fail
Upstream Patch:
https://www.privoxy.org/gitweb/?p=privoxy.git;a=commit;h=064eac5fd0 https://www.privoxy.org/gitweb/?p=privoxy.git;a=commit;h=fdee85c0bf3
External References:
https://www.privoxy.org/3.0.29/user-manual/whatsnew.html
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw in Privoxy?
The vulnerability ID for this flaw in Privoxy is CVE-2021-20215.
What is the severity level of CVE-2021-20215?
The severity level of CVE-2021-20215 is high with a CVSS score of 7.5.
How does this vulnerability in Privoxy affect the system?
This vulnerability can lead to a system crash due to memory leaks in the show-status CGI handler when memory allocations fail.
What is the affected software version of Privoxy?
The affected software version of Privoxy is any version before 3.0.29.
How can I fix CVE-2021-20215 in Privoxy?
To fix CVE-2021-20215 in Privoxy, upgrade to version 3.0.29 or later.