Reachable Assertion in privoxy - CVE-2021-20217
Published: February 1, 2021 / Updated: February 7, 2021
Vulnerability identifier: #VU50155
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20217
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion. A remote attacker can send a specially crafted CGI request to the affected server and perform a denial of service (DoS) attack.
Affected software
privoxy
Arch Linux
Gentoo Linux
Fedora
Ubuntu
privoxy (Ubuntu package)
privoxy
Arch Linux
Gentoo Linux
Fedora
Ubuntu
privoxy (Ubuntu package)
privoxy
How to mitigate CVE-2021-20217
Install updates from vendor's website.
privoxy - update to 3.0.31
privoxy (Ubuntu package) - addressed in versions 3.0.24-1ubuntu0.1, 3.0.26-5ubuntu0.1, 3.0.28-2ubuntu0.1, 3.0.28-3ubuntu0.1
privoxy - addressed in versions 3.0.31-1.el8, 3.0.31-1.fc32, 3.0.31-1.fc33
privoxy (Ubuntu package) - addressed in versions 3.0.24-1ubuntu0.1, 3.0.26-5ubuntu0.1, 3.0.28-2ubuntu0.1, 3.0.28-3ubuntu0.1
privoxy - addressed in versions 3.0.31-1.el8, 3.0.31-1.fc32, 3.0.31-1.fc33