CVE-2015-1030Missing Release of Memory after Effective Lifetime in Privoxy

Severity
5.0MEDIUMNVD
EPSS
0.5%
top 32.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 20
Latest updateMay 17

Description

Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy before 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests that are rejected because the socket limit is reached.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/privoxy< privoxy 3.0.21-5 (bookworm)
Debianprivoxy/privoxy< 3.0.21-5+3
NVDprivoxy/privoxy3.0.21

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mw79-95c5-8ph4: Memory leak in the rfc2553_connect_to function in jbsocket2022-05-17
OSV
CVE-2015-1030: Memory leak in the rfc2553_connect_to function in jbsocket2015-01-20

📋Vendor Advisories

2
Debian
CVE-2015-1030: privoxy - Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy before 3...2015
Red Hat
privoxy: potential flaws fixed in version 3.0.222014-11-28

💬Community

1
Bugzilla
CVE-2015-1030 privoxy: potential flaws fixed in version 3.0.222014-12-01
CVE-2015-1030 — Debian Privoxy vulnerability | cvebase