QID 198306

Date Published: 2021-03-31

QID 198306: Ubuntu Security Notification for Privoxy Vulnerabilities (USN-4886-1)

It was discovered that Privoxy incorrectly handled CGI requests.

It was discovered that Privoxy incorrectly handled certain regular expressions.

It was discovered that Privoxy incorrectly handled client tags.

It was discovered that Privoxy incorrectly handled client tags.

An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2020-35502, CVE-2021-20209, CVE-2021-20210, CVE-2021-20213, CVE-2021-20215, CVE-2021-20216, CVE-2021-20217, CVE-2021-20272, CVE-2021-20273, CVE-2021-20275)

An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2021-20212, CVE-2021-20276)

An attacker could possibly use this issue to cause Privoxy to consume resources, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-20211)

An attacker could possibly use this issue to cause Privoxy to consume resources, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-20214)

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Refer to Ubuntu advisory USN-4886-1 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-4886-1 16.04 (Xenial) on src privoxy URL Logo launchpad.net/ubuntu/+source/privoxy/3.0.24-1ubuntu0.1
    USN-4886-1 18.04 (bionic) on src privoxy URL Logo launchpad.net/ubuntu/+source/privoxy/3.0.26-5ubuntu0.1
    USN-4886-1 20.04 (focal) on src privoxy URL Logo launchpad.net/ubuntu/+source/privoxy/3.0.28-2ubuntu0.1
    USN-4886-1 20.10 (groovy) on src privoxy URL Logo launchpad.net/ubuntu/+source/privoxy/3.0.28-3ubuntu0.1