CVE-2021-20274: Null Pointer Dereference
Published Mar 8, 2021
·Updated
A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves.
Affected Software
2 affected componentsFixes available
redhat/privoxy<3.0.32
3.0.32
Privoxy privoxy<3.0.32
Remediation
Patch Available
Event History
Mar 9, 2021
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-20274?
CVE-2021-20274 is a vulnerability found in Privoxy versions before 3.0.32 which may cause a crash due to a NULL-pointer dereference when the socks server misbehaves.
2
How severe is CVE-2021-20274?
CVE-2021-20274 has a severity rating of 7.5 (high).
3
How does CVE-2021-20274 affect Privoxy?
CVE-2021-20274 affects Privoxy versions before 3.0.32.
4
What is the Common Weakness Enumeration (CWE) associated with CVE-2021-20274?
The Common Weakness Enumeration (CWE) associated with CVE-2021-20274 is CWE-476.
5
How can I fix the CVE-2021-20274 vulnerability?
To fix the CVE-2021-20274 vulnerability, update Privoxy to version 3.0.32 or later.