Input validation error in privoxy - CVE-2016-1983
Published: January 27, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32346
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1983
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header.
Affected software
privoxy
Amazon Linux AMI
Fedora
privoxy (Alpine package)
privoxy
Amazon Linux AMI
Fedora
privoxy (Alpine package)
privoxy
How to mitigate CVE-2016-1983
Install update from vendor's website.
privoxy - update to 3.0.24
privoxy (Alpine package) - update to 3.0.24-r0
privoxy - addressed in versions 3.0.23-2.el6, 3.0.23-3.el7, 3.0.23-3.fc22, 3.0.23-3.fc23
privoxy (Alpine package) - update to 3.0.24-r0
privoxy - addressed in versions 3.0.23-2.el6, 3.0.23-3.el7, 3.0.23-3.fc22, 3.0.23-3.fc23
External References
- http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/parsers.c?r1=1.302&r2=1.303
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176475.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176492.html
- http://www.debian.org/security/2016/dsa-3460
- http://www.openwall.com/lists/oss-security/2016/01/21/4
- http://www.openwall.com/lists/oss-security/2016/01/22/3
- http://www.privoxy.org/announce.txt