Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in Privoxy
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Privoxy
ID: USN-4886-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 14.04 ESM, Ubuntu 20.04 LTS, Ubuntu 20.10
Datum: Mo, 22. März 2021, 23:09
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20273
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20213
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20214
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20272
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20276
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20216
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20275
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20212
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35502
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20210
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20211
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20217
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20215
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20209
Applikationen: Privoxy

Originalnachricht


--===============9037709698167966346==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="s5hidg7u5opsk7sp"
Content-Disposition: inline


--s5hidg7u5opsk7sp
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4886-1
March 22, 2021

privoxy vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in Privoxy.

Software Description:
- privoxy: Privacy enhancing HTTP Proxy

Details:

It was discovered that Privoxy incorrectly handled CGI requests. An attacker
could possibly use this issue to cause a denial of service or obtain sensitive
information. (CVE-2020-35502, CVE-2021-20209, CVE-2021-20210,
CVE-2021-20213, CVE-2021-20215, CVE-2021-20216, CVE-2021-20217,
CVE-2021-20272, CVE-2021-20273, CVE-2021-20275)

It was discovered that Privoxy incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause a denial of
service or obtain sensitive information. (CVE-2021-20212, CVE-2021-20276)

It was discovered that Privoxy incorrectly handled client tags. An attacker
could possibly use this issue to cause Privoxy to consume resources, resulting
in a denial of service. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-20211)

It was discovered that Privoxy incorrectly handled client tags. An attacker
could possibly use this issue to cause Privoxy to consume resources, resulting
in a denial of service. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 20.10. (CVE-2021-20214)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
privoxy 3.0.28-3ubuntu0.1

Ubuntu 20.04 LTS:
privoxy 3.0.28-2ubuntu0.1

Ubuntu 18.04 LTS:
privoxy 3.0.26-5ubuntu0.1

Ubuntu 16.04 LTS:
privoxy 3.0.24-1ubuntu0.1

Ubuntu 14.04 ESM:
privoxy 3.0.21-7+deb8u1ubuntu0.1~esm1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-4886-1
CVE-2020-35502, CVE-2021-20209, CVE-2021-20210, CVE-2021-20211,
CVE-2021-20212, CVE-2021-20213, CVE-2021-20214, CVE-2021-20215,
CVE-2021-20216, CVE-2021-20217, CVE-2021-20272, CVE-2021-20273,
CVE-2021-20275, CVE-2021-20276

Package Information:
https://launchpad.net/ubuntu/+source/privoxy/3.0.28-3ubuntu0.1
https://launchpad.net/ubuntu/+source/privoxy/3.0.28-2ubuntu0.1
https://launchpad.net/ubuntu/+source/privoxy/3.0.26-5ubuntu0.1
https://launchpad.net/ubuntu/+source/privoxy/3.0.24-1ubuntu0.1

--s5hidg7u5opsk7sp
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEECtyyz6azUy6AZBzSkGeI6zGnN/8FAmBYz8wACgkQkGeI6zGn
N/8j3A/+N+FGji67v/KiLeROiixBZ/cMu75kCymaKL91lNfpFDD45Ja/2OFSDDWX
xwaMjj07LACp3xE/IfDBKwE20PHgtG6aHTxBP/yqTEI5EPgeNWlKsmp2RQPEbXEq
cLEbeAW5FAsLBCnjbG27Uc4Cgv3mmFnuZt+vwZYRfQrZW88+K/2WcGdK41IlQQ0w
WkE/5+Zqm520eMPfuDg6QDIFIOgP370T6lEaWk5SkdHu3p4pcPoabY6qJZoM/aRe
8Kns4jmAjzbsIDi8nvQq5gi9y/uxNFpsAsE1U/STDqn6qiAYYi/Gh5n2AVJ3Gm+B
NGB8pap+5/q5QPM0jacKE6+JD1QU8k1UYX4L2NymXzkSvMugz3f50ynjdm1UuxAE
F3BqFtA8c5dKxr0kvfBE2dPv1+Jgg38jjtftrQJ6DY60bamdJvJ1XLkYVUB3wTbP
hvjLFxKkMBeZP8bEW0SQClTSpW+XyJ1tbo4HLvYN75KtJx8+3CUNxFDjISQXBucp
BN71/+S46QWc5lNqWZ5nb0E3cLXd03OZVhd/DF76cpYCo0ds+OX6W/73/PAiMwdb
ZVH9blBVOl3XjG5/Ea6uwfU9asHJhtjsj45lGYOxWuhJ8gpmoeQ49aW36AIjuCjj
VX6AocabEg6H6MS3cun57Zow+6IO1LeYWPiJX+Qixkq9gIBCiL8=
=mzGb
-----END PGP SIGNATURE-----

--s5hidg7u5opsk7sp--


--===============9037709698167966346==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung