First published: Mon Feb 01 2021(Updated: )
A flaw was found in privoxy before version 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. References: <a href="https://www.openwall.com/lists/oss-security/2021/01/31/2">https://www.openwall.com/lists/oss-security/2021/01/31/2</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/privoxy | <3.0.31 | 3.0.31 |
Privoxy Privoxy | <3.0.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-20217.
The severity of CVE-2021-20217 is high with a severity value of 7.5.
The affected software by CVE-2021-20217 is Privoxy version up to exclusive 3.0.31.
This vulnerability can be exploited by triggering an assertion failure with a crafted CGI request, leading to denial of service.
You can fix CVE-2021-20217 by updating Privoxy to version 3.0.31 or later.