7.8
CVSSv2

CVE-2021-20214

Published: 25/03/2021 Updated: 14/12/2021
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

A flaw was found in Privoxy in versions prior to 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

privoxy privoxy

Mailing Lists

It looks like Red Hat has assigned CVE ids for these issues now, but not yet told Mitre to publish them: CVE-2020-35502 privoxy: memory leaks when a response is buffered bugzillaredhatcom/show_bugcgi?id=1928749 CVE-2021-20209 privoxy: memory leak in the show-status CGI handler when no action files are configured bugzillaredhat ...
Fabian Keil <freebsd-listen () fabiankeil de> wrote on 2020-11-29: Here are the updated ChangeLog entries with CVEs: - Security/Reliability: - Fixed memory leaks when a response is buffered and the buffer limit is reached or Privoxy is running out of memory Commits bbd53f1010b and 4490d451f9b OVE-20201118-0001 CVE-2020-35 ...