Memory leak in privoxy - CVE-2021-20212
Published: December 29, 2020 / Updated: February 3, 2021
Vulnerability identifier: #VU49174
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20212
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak if multiple filters are executed and the last one is skipped due to a pcre error. A remote attacker can force the application to leak memory and perform denial of service attack.
Affected software
privoxy
Gentoo Linux
Fedora
Ubuntu
privoxy (Ubuntu package)
privoxy
Gentoo Linux
Fedora
Ubuntu
privoxy (Ubuntu package)
privoxy
How to mitigate CVE-2021-20212
Install updates from vendor's website.
privoxy - update to 3.0.29
privoxy (Ubuntu package) - addressed in versions 3.0.24-1ubuntu0.1, 3.0.26-5ubuntu0.1, 3.0.28-2ubuntu0.1, 3.0.28-3ubuntu0.1
privoxy - addressed in versions 3.0.31-1.el7, 3.0.32-1.el7
privoxy (Ubuntu package) - addressed in versions 3.0.24-1ubuntu0.1, 3.0.26-5ubuntu0.1, 3.0.28-2ubuntu0.1, 3.0.28-3ubuntu0.1
privoxy - addressed in versions 3.0.31-1.el7, 3.0.32-1.el7