First published: Mon Mar 08 2021(Updated: )
A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Privoxy Privoxy | <3.0.32 | |
Debian Debian Linux | =9.0 | |
redhat/privoxy | <3.0.32 | 3.0.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this flaw is CVE-2021-20272.
The severity of CVE-2021-20272 is high with a CVSS score of 7.5.
The affected software for CVE-2021-20272 is Privoxy versions before 3.0.32 and Debian Linux version 9.0.
The impact of CVE-2021-20272 is a server crash due to an assertion failure triggered by a crafted CGI request.
Yes, there are references related to CVE-2021-20272. You can find them at the following links: [Link 1](https://bugzilla.redhat.com/show_bug.cgi?id=1936651), [Link 2](https://lists.debian.org/debian-lts-announce/2021/03/msg00009.html), [Link 3](https://security.gentoo.org/glsa/202107-16).