CVE-2015-1382
published 2015-02-03CVE-2015-1382: parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.77%
84.7th percentile
parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | privoxy | < privoxy 3.0.21-7 (bookworm) | privoxy 3.0.21-7 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| privoxy | privoxy | <= 3.0.22 | — |
| privoxy | privoxy | >= 0 < 3.0.21-7 | 3.0.21-7 |
| privoxy | privoxy | >= 0 < 3.0.21-7 | 3.0.21-7 |
| privoxy | privoxy | >= 0 < 3.0.21-7 | 3.0.21-7 |
| privoxy | privoxy | >= 0 < 3.0.21-7 | 3.0.21-7 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
privoxy: denial of service (invalid memory read) issue in parsers.c
vendor_redhat·2015-01-26·CVSS 5.0
CVE-2015-1382 [MEDIUM] CWE-125 privoxy: denial of service (invalid memory read) issue in parsers.c
privoxy: denial of service (invalid memory read) issue in parsers.c
parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.
Package: privoxy (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-1382: privoxy - parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of ...
vendor_debian·2015·CVSS 5.0
CVE-2015-1382 [MEDIUM] CVE-2015-1382: privoxy - parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of ...
parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.
Scope: local
bookworm: resolved (fixed in 3.0.21-7)
bullseye: resolved (fixed in 3.0.21-7)
forky: resolved (fixed in 3.0.21-7)
sid: resolved (fixed in 3.0.21-7)
trixie: resolved (fixed in 3.0.21-7)
GHSA
GHSA-6p8r-62jm-r2v7: parsers
ghsa_unreviewed·2022-05-14
CVE-2015-1382 [MEDIUM] CWE-20 GHSA-6p8r-62jm-r2v7: parsers
parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.
OSV
CVE-2015-1382: parsers
osv·2015-02-03·CVSS 5.0
CVE-2015-1382 [MEDIUM] CVE-2015-1382: parsers
parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1382 privoxy: denial of service (invalid memory read) issue in parsers.c
bugzilla·2015-03-18·CVSS 5.0
CVE-2015-1382 [MEDIUM] CVE-2015-1382 privoxy: denial of service (invalid memory read) issue in parsers.c
CVE-2015-1382 privoxy: denial of service (invalid memory read) issue in parsers.c
Privoxy 3.0.23 fixes following security issue:
- Fixed an 'invalid read' bug which could at least theoretically
cause Privoxy to crash.
http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/parsers.c?r1=1.297&r2=1.298
Original report: http://seclists.org/oss-sec/2015/q1/259
Bugzilla
CVE-2015-1380 privoxy: denial of service in case of client requests with incorrect chunk-encoded body
bugzilla·2015-01-26·CVSS 5.0
CVE-2015-1380 [MEDIUM] CVE-2015-1380 privoxy: denial of service in case of client requests with incorrect chunk-encoded body
CVE-2015-1380 privoxy: denial of service in case of client requests with incorrect chunk-encoded body
It was reported [1] that Privoxy 3.0.23 contains fixes for the following security issues:
- Fixed a DoS issue in case of client requests with incorrect
chunk-encoded body. When compiled with assertions enabled
(the default) they could previously cause Privoxy to abort().
Reported by Matthew Daley.
http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/jcc.c?r1=1.433&r2=1.434
- Fixed multiple segmentation faults and memory leaks in the
pcrs code. This fix also increases the chances that an invalid
pcrs command is rejected as such. Previously some invalid commands
would be loaded without error. Note that Privoxy's pcrs sources
(action and filter files) are considered trustworthy input an
http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/ChangeLog?revision=1.197&view=markuphttp://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/parsers.c?r1=1.297&r2=1.298http://lists.opensuse.org/opensuse-updates/2015-02/msg00031.htmlhttp://secunia.com/advisories/62775http://secunia.com/advisories/62899http://www.debian.org/security/2015/dsa-3145http://www.openwall.com/lists/oss-security/2015/01/26/4http://www.openwall.com/lists/oss-security/2015/01/27/20http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/ChangeLog?revision=1.197&view=markuphttp://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/parsers.c?r1=1.297&r2=1.298http://lists.opensuse.org/opensuse-updates/2015-02/msg00031.htmlhttp://secunia.com/advisories/62775http://secunia.com/advisories/62899http://www.debian.org/security/2015/dsa-3145http://www.openwall.com/lists/oss-security/2015/01/26/4http://www.openwall.com/lists/oss-security/2015/01/27/20
2015-02-03
Published