CVE-2015-1380Improper Input Validation in Privoxy

Severity
5.0MEDIUMNVD
EPSS
1.0%
top 22.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 3
Latest updateMay 14

Description

jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

Debianprivoxy/privoxy< 3.0.21-7+3
NVDprivoxy/privoxy3.0.22
NVDoracle/solaris11.2
NVDopensuse/opensuse13.1, 13.2+1

🔴Vulnerability Details

3
GHSA
GHSA-9xgq-968g-4cjx: jcc2022-05-14
CVEList
CVE-2015-1380: jcc2015-02-03
OSV
CVE-2015-1380: jcc2015-02-03

📋Vendor Advisories

2
Red Hat
privoxy: denial of service in case of client requests with incorrect chunk-encoded body2015-01-26
Debian
CVE-2015-1380: privoxy - jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of serv...2015

💬Community

1
Bugzilla
CVE-2015-1380 privoxy: denial of service in case of client requests with incorrect chunk-encoded body2015-01-26
CVE-2015-1380 — Improper Input Validation in Privoxy | cvebase