MGASA-2015-0003
Dashboard / Vulnerabilities / MGASA-2015-0003
MGASA-2015-0003
Summary: Updated privoxy package fixes security vulnerabilities
Details: Updated privoxy packages fix security issues: A memory leak occurred in privoxy 3.0.21 compiled with IPv6 support when rejecting client connections due to the socket limit being reached. (CID 66382) A use-after-free bug was found in privoxy 3.0.21 and two additional potential use-after-free issues were detected by Coverity scan. (CID 66394, CID 66376, CID 66391) Also fixed is a file descriptor leak in an error path in jbsockets.c. (CID 66368)
References: https://advisories.mageia.org/MGASA-2015-0003.html, https://bugs.mageia.org/show_bug.cgi?id=14892, http://www.privoxy.org/announce.txt
Affected packages
Package
Name: privoxy
Purl: pkg:rpm/mageia/privoxy?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
