CVE-2015-1380
published 2015-02-03CVE-2015-1380: jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.40%
87.6th percentile
jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | privoxy | < privoxy 3.0.21-7 (bookworm) | privoxy 3.0.21-7 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| privoxy | privoxy | <= 3.0.22 | — |
| privoxy | privoxy | >= 0 < 3.0.21-7 | 3.0.21-7 |
| privoxy | privoxy | >= 0 < 3.0.21-7 | 3.0.21-7 |
| privoxy | privoxy | >= 0 < 3.0.21-7 | 3.0.21-7 |
| privoxy | privoxy | >= 0 < 3.0.21-7 | 3.0.21-7 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9xgq-968g-4cjx: jcc
ghsa_unreviewed·2022-05-14
CVE-2015-1380 [MEDIUM] CWE-20 GHSA-9xgq-968g-4cjx: jcc
jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
OSV
CVE-2015-1380: jcc
osv·2015-02-03·CVSS 5.0
CVE-2015-1380 [MEDIUM] CVE-2015-1380: jcc
jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
Red Hat
privoxy: denial of service in case of client requests with incorrect chunk-encoded body
vendor_redhat·2015-01-26·CVSS 5.0
CVE-2015-1380 [MEDIUM] CWE-617 privoxy: denial of service in case of client requests with incorrect chunk-encoded body
privoxy: denial of service in case of client requests with incorrect chunk-encoded body
jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
Package: privoxy (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-1380: privoxy - jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of serv...
vendor_debian·2015·CVSS 5.0
CVE-2015-1380 [MEDIUM] CVE-2015-1380: privoxy - jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of serv...
jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
Scope: local
bookworm: resolved (fixed in 3.0.21-7)
bullseye: resolved (fixed in 3.0.21-7)
forky: resolved (fixed in 3.0.21-7)
sid: resolved (fixed in 3.0.21-7)
trixie: resolved (fixed in 3.0.21-7)
No detection rules found.
No public exploits indexed.
http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/ChangeLog?revision=1.197&view=markuphttp://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/currentjcc.c/?r1=1.433&r2=1.434http://lists.opensuse.org/opensuse-updates/2015-02/msg00031.htmlhttp://secunia.com/advisories/62899http://www.openwall.com/lists/oss-security/2015/01/26/4http://www.openwall.com/lists/oss-security/2015/01/27/20http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.securityfocus.com/bid/72355http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/ChangeLog?revision=1.197&view=markuphttp://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/currentjcc.c/?r1=1.433&r2=1.434http://lists.opensuse.org/opensuse-updates/2015-02/msg00031.htmlhttp://secunia.com/advisories/62899http://www.openwall.com/lists/oss-security/2015/01/26/4http://www.openwall.com/lists/oss-security/2015/01/27/20http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.securityfocus.com/bid/72355
2015-02-03
Published