privoxy: two denial of service flaws
| Package(s): | privoxy | CVE #(s): | CVE-2016-1982 CVE-2016-1983 | ||||||||||||||||||||||||||||||||
| Created: | January 25, 2016 | Updated: | February 9, 2016 | ||||||||||||||||||||||||||||||||
| Description: | From the Arch Linux advisory:
- CVE-2016-1982 (denial of service): A vulnerability was discovered in a way the privoxy deals with corrupted chunk-encoded content. A maliciously crafted input can result in a remote denial of service. - CVE-2016-1983 (denial of service): A vulnerability was found in a way the privoxy processes specific client requests. A request with "Host" header empty could result in an invalid read. | ||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||
