Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2021.0570
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2021-0570)
Zusammenfassung:The remote host is missing an update for the 'privoxy' package(s) announced via the MGASA-2021-0570 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'privoxy' package(s) announced via the MGASA-2021-0570 advisory.

Vulnerability Insight:
Updated privoxy packages fix security vulnerabilities:

A security issue has been found in Privoxy before version 3.0.33.
get_url_spec_param() did not free memory of compiled pattern spec
before bailing (CVE-2021-44540).

A security issue has been found in Privoxy before version 3.0.33.
process_encrypted_request_headers() did not free header memory when
failing to get the request destination (CVE-2021-44541).

A security issue has been found in Privoxy before version 3.0.33.
send_http_request() leaked memory when handling errors (CVE-2021-44542).

A security issue has been found in Privoxy before version 3.0.33.
cgi_error_no_template() did not encode the template name, which could
lead to cross-site scripting when Privoxy is configured to service, serve the
user-manual itself (CVE-2021-44543).

Affected Software/OS:
'privoxy' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2021-44540
https://www.privoxy.org/3.0.33/user-manual/whatsnew.html,
https://www.privoxy.org/gitweb/?p=privoxy.git;a=commit;h=652b4b7cb0
Common Vulnerability Exposure (CVE) ID: CVE-2021-44541
Common Vulnerability Exposure (CVE) ID: CVE-2021-44542
https://www.privoxy.org/gitweb/?p=privoxy.git;a=commit;h=c48d1d6d08
Common Vulnerability Exposure (CVE) ID: CVE-2021-44543
https://www.privoxy.org/gitweb/?p=privoxy.git;a=commit;h=0e668e9409c
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.