CVE-2015-1381
published 2015-02-03CVE-2015-1381: Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or memory…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.77%
84.7th percentile
Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or memory consumption) via unspecified vectors.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | privoxy | < privoxy 3.0.21-7 (bookworm) | privoxy 3.0.21-7 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| privoxy | privoxy | <= 3.0.22 | — |
| privoxy | privoxy | >= 0 < 3.0.21-7 | 3.0.21-7 |
| privoxy | privoxy | >= 0 < 3.0.21-7 | 3.0.21-7 |
| privoxy | privoxy | >= 0 < 3.0.21-7 | 3.0.21-7 |
| privoxy | privoxy | >= 0 < 3.0.21-7 | 3.0.21-7 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ggfg-5cgr-jxg9: Multiple unspecified vulnerabilities in pcrs
ghsa_unreviewed·2022-05-14
CVE-2015-1381 [MEDIUM] GHSA-ggfg-5cgr-jxg9: Multiple unspecified vulnerabilities in pcrs
Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or memory consumption) via unspecified vectors.
OSV
CVE-2015-1381: Multiple unspecified vulnerabilities in pcrs
osv·2015-02-03·CVSS 5.0
CVE-2015-1381 [MEDIUM] CVE-2015-1381: Multiple unspecified vulnerabilities in pcrs
Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or memory consumption) via unspecified vectors.
Red Hat
privoxy: denial of service (segmentation faults, memory leaks) issues in pcrs.c
vendor_redhat·2015-01-26·CVSS 5.0
CVE-2015-1381 [MEDIUM] CWE-401 privoxy: denial of service (segmentation faults, memory leaks) issues in pcrs.c
privoxy: denial of service (segmentation faults, memory leaks) issues in pcrs.c
Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or memory consumption) via unspecified vectors.
Package: privoxy (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-1381: privoxy - Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow re...
vendor_debian·2015·CVSS 5.0
CVE-2015-1381 [MEDIUM] CVE-2015-1381: privoxy - Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow re...
Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or memory consumption) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 3.0.21-7)
bullseye: resolved (fixed in 3.0.21-7)
forky: resolved (fixed in 3.0.21-7)
sid: resolved (fixed in 3.0.21-7)
trixie: resolved (fixed in 3.0.21-7)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1381 privoxy: denial of service (segmentation faults, memory leaks) issues in pcrs.c
bugzilla·2015-03-18·CVSS 5.0
CVE-2015-1381 [MEDIUM] CVE-2015-1381 privoxy: denial of service (segmentation faults, memory leaks) issues in pcrs.c
CVE-2015-1381 privoxy: denial of service (segmentation faults, memory leaks) issues in pcrs.c
Privoxy 3.0.23 fixes following security issue:
- Fixed multiple segmentation faults and memory leaks in the
pcrs code. This fix also increases the chances that an invalid
pcrs command is rejected as such. Previously some invalid commands
would be loaded without error. Note that Privoxy's pcrs sources
(action and filter files) are considered trustworthy input and
should not be writable by untrusted third-parties.
http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/pcrs.c?r1=1.46&r2=1.47
Original report: http://seclists.org/oss-sec/2015/q1/259
Bugzilla
CVE-2015-1380 privoxy: denial of service in case of client requests with incorrect chunk-encoded body
bugzilla·2015-01-26·CVSS 5.0
CVE-2015-1380 [MEDIUM] CVE-2015-1380 privoxy: denial of service in case of client requests with incorrect chunk-encoded body
CVE-2015-1380 privoxy: denial of service in case of client requests with incorrect chunk-encoded body
It was reported [1] that Privoxy 3.0.23 contains fixes for the following security issues:
- Fixed a DoS issue in case of client requests with incorrect
chunk-encoded body. When compiled with assertions enabled
(the default) they could previously cause Privoxy to abort().
Reported by Matthew Daley.
http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/jcc.c?r1=1.433&r2=1.434
- Fixed multiple segmentation faults and memory leaks in the
pcrs code. This fix also increases the chances that an invalid
pcrs command is rejected as such. Previously some invalid commands
would be loaded without error. Note that Privoxy's pcrs sources
(action and filter files) are considered trustworthy input an
http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/ChangeLog?revision=1.197&view=markuphttp://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/pcrs.c?r1=1.46&r2=1.47http://lists.opensuse.org/opensuse-updates/2015-02/msg00031.htmlhttp://secunia.com/advisories/62775http://secunia.com/advisories/62899http://www.debian.org/security/2015/dsa-3145http://www.openwall.com/lists/oss-security/2015/01/26/4http://www.openwall.com/lists/oss-security/2015/01/27/20http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/ChangeLog?revision=1.197&view=markuphttp://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/pcrs.c?r1=1.46&r2=1.47http://lists.opensuse.org/opensuse-updates/2015-02/msg00031.htmlhttp://secunia.com/advisories/62775http://secunia.com/advisories/62899http://www.debian.org/security/2015/dsa-3145http://www.openwall.com/lists/oss-security/2015/01/26/4http://www.openwall.com/lists/oss-security/2015/01/27/20
2015-02-03
Published