CVE-2021-20217: High severity privoxy vulnerability
A flaw was found in privoxy before version 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service.
References:
https://www.openwall.com/lists/oss-security/2021/01/31/2
Other sources
A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system availability.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this flaw?
The vulnerability ID is CVE-2021-20217.
What is the severity of CVE-2021-20217?
The severity of CVE-2021-20217 is high with a severity value of 7.5.
What is the affected software by CVE-2021-20217?
The affected software by CVE-2021-20217 is Privoxy version up to exclusive 3.0.31.
How can this vulnerability be exploited?
This vulnerability can be exploited by triggering an assertion failure with a crafted CGI request, leading to denial of service.
How can I fix CVE-2021-20217?
You can fix CVE-2021-20217 by updating Privoxy to version 3.0.31 or later.