MGASA-2016-0055
Dashboard / Vulnerabilities / MGASA-2016-0055
Summary: Updated privoxy packages fix security vulnerabilities
Details: This update fixes two denial-of-service vulnerabilities that have been discovered in privoxy 3.0.23: The remove_chunked_transfer_coding function in filters.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via crafted chunk-encoded content. (CVE-2016-1982) The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header. (CVE-2016-1983)
References: https://advisories.mageia.org/MGASA-2016-0055.html, https://bugs.mageia.org/show_bug.cgi?id=17566
Affected packages
Package
Name: privoxy
Purl: pkg:rpm/mageia/privoxy?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
