USN-4886-1
Dashboard / Vulnerabilities / USN-4886-1
USN-4886-1
Summary: privoxy vulnerabilities
Details: It was discovered that Privoxy incorrectly handled CGI requests. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2020-35502, CVE-2021-20209, CVE-2021-20210, CVE-2021-20213, CVE-2021-20215, CVE-2021-20216, CVE-2021-20217, CVE-2021-20272, CVE-2021-20273, CVE-2021-20275) It was discovered that Privoxy incorrectly handled certain regular expressions. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2021-20212, CVE-2021-20276) It was discovered that Privoxy incorrectly handled client tags. An attacker could possibly use this issue to cause Privoxy to consume resources, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-20211) It was discovered that Privoxy incorrectly handled client tags. An attacker could possibly use this issue to cause Privoxy to consume resources, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-20214)
References: https://ubuntu.com/security/notices/USN-4886-1, https://ubuntu.com/security/CVE-2020-35502, https://ubuntu.com/security/CVE-2021-20209, https://ubuntu.com/security/CVE-2021-20210, https://ubuntu.com/security/CVE-2021-20211, https://ubuntu.com/security/CVE-2021-20212, https://ubuntu.com/security/CVE-2021-20213, https://ubuntu.com/security/CVE-2021-20214, https://ubuntu.com/security/CVE-2021-20215, https://ubuntu.com/security/CVE-2021-20216, https://ubuntu.com/security/CVE-2021-20217, https://ubuntu.com/security/CVE-2021-20272, https://ubuntu.com/security/CVE-2021-20273, https://ubuntu.com/security/CVE-2021-20275, https://ubuntu.com/security/CVE-2021-20276
Affected packages
Package
Name: privoxy
Purl: pkg:deb/ubuntu/privoxy?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
