Lucene search

K
osvGoogleOSV:DLA-142-1
HistoryJan 29, 2015 - 12:00 a.m.

privoxy - security update

2015-01-2900:00:00
Google
osv.dev
11

EPSS

0.05

Percentile

93.0%

Several vulnerabilities have been fixed in privoxy, a privacy enhancing
HTTP proxy:

unmap(): Prevent use-after-free if the map only consists of one item.

pcrs_execute(): Consistently set *result to NULL in case of errors.
Should make use-after-free in the caller less likely.

  • CVE-2015-1381
    Fix multiple segmentation faults and memory leaks in the pcrs code.
  • CVE-2015-1382
    Fix invalid read to prevent potential crashes.

We recommend that you upgrade your privoxy packages.

For Debian 6 Squeeze, these issues have been fixed in privoxy version 3.0.16-1+deb6u1