CVE-2015-1031
published 2015-02-10CVE-2015-1031: Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote attackers to have unspecified impact via vectors related to (1) the unmap…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.41%
82.3th percentile
Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote attackers to have unspecified impact via vectors related to (1) the unmap function in list.c or (2) "two additional unconfirmed use-after-free complaints made by Coverity scan." NOTE: some of these details are obtained from third party information.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | privoxy | < privoxy 3.0.21-5 (bookworm) | privoxy 3.0.21-5 (bookworm) |
| privoxy | privoxy | <= 3.0.21 | — |
| privoxy | privoxy | >= 0 < 3.0.21-5 | 3.0.21-5 |
| privoxy | privoxy | >= 0 < 3.0.21-5 | 3.0.21-5 |
| privoxy | privoxy | >= 0 < 3.0.21-5 | 3.0.21-5 |
| privoxy | privoxy | >= 0 < 3.0.21-5 | 3.0.21-5 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-1031: privoxy - Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote at...
vendor_debian·2015·CVSS 7.5
CVE-2015-1031 [HIGH] CVE-2015-1031: privoxy - Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote at...
Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote attackers to have unspecified impact via vectors related to (1) the unmap function in list.c or (2) "two additional unconfirmed use-after-free complaints made by Coverity scan." NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 3.0.21-5)
bullseye: resolved (fixed in 3.0.21-5)
forky: resolved (fixed in 3.0.21-5)
sid: resolved (fixed in 3.0.21-5)
trixie: resolved (fixed in 3.0.21-5)
Red Hat
privoxy: several use-after-free issues in list.c
vendor_redhat·2014-11-28·CVSS 7.5
CVE-2015-1031 [HIGH] CWE-476 privoxy: several use-after-free issues in list.c
privoxy: several use-after-free issues in list.c
Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote attackers to have unspecified impact via vectors related to (1) the unmap function in list.c or (2) "two additional unconfirmed use-after-free complaints made by Coverity scan." NOTE: some of these details are obtained from third party information.
Package: privoxy (Red Hat Enterprise Linux 5) - Will not fix
GHSA
GHSA-p49r-xm5f-3r8x: Multiple use-after-free vulnerabilities in Privoxy before 3
ghsa_unreviewed·2022-05-17
CVE-2015-1031 [HIGH] GHSA-p49r-xm5f-3r8x: Multiple use-after-free vulnerabilities in Privoxy before 3
Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote attackers to have unspecified impact via vectors related to (1) the unmap function in list.c or (2) "two additional unconfirmed use-after-free complaints made by Coverity scan." NOTE: some of these details are obtained from third party information.
OSV
CVE-2015-1031: Multiple use-after-free vulnerabilities in Privoxy before 3
osv·2015-02-10·CVSS 7.5
CVE-2015-1031 [HIGH] CVE-2015-1031: Multiple use-after-free vulnerabilities in Privoxy before 3
Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote attackers to have unspecified impact via vectors related to (1) the unmap function in list.c or (2) "two additional unconfirmed use-after-free complaints made by Coverity scan." NOTE: some of these details are obtained from third party information.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1031 privoxy: several use-after-free issues in list.c
bugzilla·2015-03-18·CVSS 7.5
CVE-2015-1031 [HIGH] CVE-2015-1031 privoxy: several use-after-free issues in list.c
CVE-2015-1031 privoxy: several use-after-free issues in list.c
Privoxy 3.0.22 fixes an immediate-use-after-free bug (CID 66394) and two additional unconfirmed use-after-free complaints made by Coverity scan (CID 66391, CID 66376).
Links:
http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/list.c?view=log&pathrev=v_3_0_22
Patch: http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/list.c?view=patch&r1=1.31&r2=1.32&pathrev=v_3_0_22
Bugzilla
CVE-2015-1030 privoxy: potential flaws fixed in version 3.0.22
bugzilla·2014-12-01·CVSS 5.0
CVE-2015-1030 [MEDIUM] CVE-2015-1030 privoxy: potential flaws fixed in version 3.0.22
CVE-2015-1030 privoxy: potential flaws fixed in version 3.0.22
The 3.0.22 release of Privoxy fixes the following potential flaws:
""
Fixed a memory leak when rejecting client connections due to
the socket limit being reached (CID 66382). This affected
Privoxy 3.0.21 when compiled with IPv6 support (on most
platforms this is the default).
Fixed an immediate-use-after-free bug (CID 66394) and two
additional unconfirmed use-after-free complaints made by
Coverity scan (CID 66391, CID 66376).
""
Version 3.0.22 is already in the Fedora and EPEL 6 testing repositories.
Reference:
http://www.privoxy.org/announce.txt
Discussion:
(In reply to Murray McAllister from comment #0)
> Fixed a memory leak when rejecting client connections due to
> the socket limit being reached (CID 66382). This af
http://secunia.com/advisories/62123http://www.debian.org/security/2015/dsa-3133http://www.openwall.com/lists/oss-security/2015/01/11/1http://www.privoxy.org/announce.txthttp://secunia.com/advisories/62123http://www.debian.org/security/2015/dsa-3133http://www.openwall.com/lists/oss-security/2015/01/11/1http://www.privoxy.org/announce.txt
2015-02-10
Published