Memory leak in privoxy - CVE-2020-35502
Published: December 29, 2020 / Updated: February 3, 2021
Vulnerability identifier: #VU49170
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-35502
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak when a response is buffered and the buffer limit is reached or Privoxy is running out of memory. A remote attacker can force the application to leak memory and perform denial of service attack.
Affected software
privoxy
Gentoo Linux
Fedora
Ubuntu
privoxy (Ubuntu package)
privoxy
Gentoo Linux
Fedora
Ubuntu
privoxy (Ubuntu package)
privoxy
How to mitigate CVE-2020-35502
Install updates from vendor's website.
privoxy - update to 3.0.29
privoxy (Ubuntu package) - addressed in versions 3.0.24-1ubuntu0.1, 3.0.26-5ubuntu0.1, 3.0.28-2ubuntu0.1, 3.0.28-3ubuntu0.1
privoxy - addressed in versions 3.0.31-1.el7, 3.0.32-1.el7
privoxy (Ubuntu package) - addressed in versions 3.0.24-1ubuntu0.1, 3.0.26-5ubuntu0.1, 3.0.28-2ubuntu0.1, 3.0.28-3ubuntu0.1
privoxy - addressed in versions 3.0.31-1.el7, 3.0.32-1.el7