CVE-2016-1983
published 2016-01-27CVE-2016-1983: The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP…
PriorityP434high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.87%
85.2th percentile
The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | privoxy | < privoxy 3.0.24-1 (bookworm) | privoxy 3.0.24-1 (bookworm) |
| privoxy | privoxy | <= 3.0.23 | — |
| privoxy | privoxy | >= 0 < 3.0.24-1 | 3.0.24-1 |
| privoxy | privoxy | >= 0 < 3.0.24-1 | 3.0.24-1 |
| privoxy | privoxy | >= 0 < 3.0.24-1 | 3.0.24-1 |
| privoxy | privoxy | >= 0 < 3.0.24-1 | 3.0.24-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6frp-gfc5-q2xj: The client_host function in parsers
ghsa_unreviewed·2022-05-17
CVE-2016-1983 [HIGH] CWE-20 GHSA-6frp-gfc5-q2xj: The client_host function in parsers
The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header.
OSV
CVE-2016-1983: The client_host function in parsers
osv·2016-01-27·CVSS 7.5
CVE-2016-1983 [HIGH] CVE-2016-1983: The client_host function in parsers
The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header.
Red Hat
privoxy: invalid read via empty host header in client request
vendor_redhat·2016-01-21·CVSS 7.5
CVE-2016-1983 [HIGH] CWE-125 privoxy: invalid read via empty host header in client request
privoxy: invalid read via empty host header in client request
The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header.
Package: privoxy (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-1983: privoxy - The client_host function in parsers.c in Privoxy before 3.0.24 allows remote att...
vendor_debian·2016·CVSS 7.5
CVE-2016-1983 [HIGH] CVE-2016-1983: privoxy - The client_host function in parsers.c in Privoxy before 3.0.24 allows remote att...
The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header.
Scope: local
bookworm: resolved (fixed in 3.0.24-1)
bullseye: resolved (fixed in 3.0.24-1)
forky: resolved (fixed in 3.0.24-1)
sid: resolved (fixed in 3.0.24-1)
trixie: resolved (fixed in 3.0.24-1)
No detection rules found.
Bugzilla
CVE-2016-1983 privoxy: invalid read via empty host header in client request
bugzilla·2016-01-22·CVSS 7.5
CVE-2016-1983 [HIGH] CVE-2016-1983 privoxy: invalid read via empty host header in client request
CVE-2016-1983 privoxy: invalid read via empty host header in client request
A vulnerability was found in a way the privoxy processes specific client requests. A request with "Host" header empty could result in an invalid read.
CVE assignment:
http://seclists.org/oss-sec/2016/q1/179
External reference:
http://seclists.org/oss-sec/2016/q1/173
Upstream fix:
http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/parsers.c?r1=1.302&r2=1.303
Discussion:
Created privoxy tracking bugs for this issue:
Affects: fedora-all [bug 1300973]
Affects: epel-6 [bug 1300974]
Affects: epel-7 [bug 1300975]
---
Buffer over-read issue, possibly leading to crash. The privoxy is only included in Red Hat Enterprise Linux 5, which is in Phase 3 of its life cycle, and is therefore not planned to have this
Bugzilla
CVE-2016-1983 privoxy: invalid read via empty host header in client request [fedora-all]
bugzilla·2016-01-22·CVSS 7.5
CVE-2016-1983 [HIGH] CVE-2016-1983 privoxy: invalid read via empty host header in client request [fedora-all]
CVE-2016-1983 privoxy: invalid read via empty host header in client request [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2016-1983 privoxy: invalid read via empty host header in client request [epel-6]
bugzilla·2016-01-22·CVSS 7.5
CVE-2016-1983 [HIGH] CVE-2016-1983 privoxy: invalid read via empty host header in client request [epel-6]
CVE-2016-1983 privoxy: invalid read via empty host header in client request [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking bug for privoxy: see blocks
Bugzilla
CVE-2016-1983 privoxy: invalid read via empty host header in client request [epel-7]
bugzilla·2016-01-22·CVSS 7.5
CVE-2016-1983 [HIGH] CVE-2016-1983 privoxy: invalid read via empty host header in client request [epel-7]
CVE-2016-1983 privoxy: invalid read via empty host header in client request [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for privoxy: see blocks
http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/parsers.c?r1=1.302&r2=1.303http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176475.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176492.htmlhttp://www.debian.org/security/2016/dsa-3460http://www.openwall.com/lists/oss-security/2016/01/21/4http://www.openwall.com/lists/oss-security/2016/01/22/3http://www.privoxy.org/announce.txthttp://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/parsers.c?r1=1.302&r2=1.303http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176475.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176492.htmlhttp://www.debian.org/security/2016/dsa-3460http://www.openwall.com/lists/oss-security/2016/01/21/4http://www.openwall.com/lists/oss-security/2016/01/22/3http://www.privoxy.org/announce.txt
2016-01-27
Published