Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2021.0570
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2021-0570)
Resumen:The remote host is missing an update for the 'privoxy' package(s) announced via the MGASA-2021-0570 advisory.
Descripción:Summary:
The remote host is missing an update for the 'privoxy' package(s) announced via the MGASA-2021-0570 advisory.

Vulnerability Insight:
Updated privoxy packages fix security vulnerabilities:

A security issue has been found in Privoxy before version 3.0.33.
get_url_spec_param() did not free memory of compiled pattern spec
before bailing (CVE-2021-44540).

A security issue has been found in Privoxy before version 3.0.33.
process_encrypted_request_headers() did not free header memory when
failing to get the request destination (CVE-2021-44541).

A security issue has been found in Privoxy before version 3.0.33.
send_http_request() leaked memory when handling errors (CVE-2021-44542).

A security issue has been found in Privoxy before version 3.0.33.
cgi_error_no_template() did not encode the template name, which could
lead to cross-site scripting when Privoxy is configured to service, serve the
user-manual itself (CVE-2021-44543).

Affected Software/OS:
'privoxy' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2021-44540
https://www.privoxy.org/3.0.33/user-manual/whatsnew.html,
https://www.privoxy.org/gitweb/?p=privoxy.git;a=commit;h=652b4b7cb0
Common Vulnerability Exposure (CVE) ID: CVE-2021-44541
Common Vulnerability Exposure (CVE) ID: CVE-2021-44542
https://www.privoxy.org/gitweb/?p=privoxy.git;a=commit;h=c48d1d6d08
Common Vulnerability Exposure (CVE) ID: CVE-2021-44543
https://www.privoxy.org/gitweb/?p=privoxy.git;a=commit;h=0e668e9409c
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.