CVE-2021-20216: High severity privoxy vulnerability
A flaw was found in privoxy before version 3.0.31. A memory leak when decompression fails "unexpectedly" may lead to denial of service.
References:
https://www.openwall.com/lists/oss-security/2021/01/31/2
Other sources
A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20216.
What is the severity of CVE-2021-20216?
The severity of CVE-2021-20216 is high with a CVSS score of 7.5.
What is the highest threat from CVE-2021-20216?
The highest threat from CVE-2021-20216 is to system availability.
How does CVE-2021-20216 impact Privoxy?
CVE-2021-20216 can cause a denial of service due to a memory leak when decompression fails unexpectedly.
How can I fix CVE-2021-20216?
To fix CVE-2021-20216, upgrade Privoxy to version 3.0.31 or later.