CVE-2015-1382Improper Input Validation in Privoxy

Severity
5.0MEDIUMNVD
EPSS
2.2%
top 15.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 3
Latest updateMay 14

Description

parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

debiandebian/privoxy< privoxy 3.0.21-7 (bookworm)
Debianprivoxy/privoxy< 3.0.21-7+3
NVDprivoxy/privoxy3.0.22
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Debian Linux 7.0

🔴Vulnerability Details

2
GHSA
GHSA-6p8r-62jm-r2v7: parsers2022-05-14
OSV
CVE-2015-1382: parsers2015-02-03

📋Vendor Advisories

2
Red Hat
privoxy: denial of service (invalid memory read) issue in parsers.c2015-01-26
Debian
CVE-2015-1382: privoxy - parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of ...2015

💬Community

2
Bugzilla
CVE-2015-1382 privoxy: denial of service (invalid memory read) issue in parsers.c2015-03-18
Bugzilla
CVE-2015-1380 privoxy: denial of service in case of client requests with incorrect chunk-encoded body2015-01-26
CVE-2015-1382 — Improper Input Validation in Privoxy | cvebase