CVE-2021-20276 - log back

CVE-2021-20276 edited at 06 Mar 2021 09:27:32
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1935974
+ https://www.openwall.com/lists/oss-security/2021/03/06/2
https://www.privoxy.org/announce.txt
https://www.privoxy.org/gitweb/?p=privoxy.git;a=commitdiff;h=28512e5b62457f0ff6f2d72e3e5c9226b9e0203d
Notes
CVE-2021-20276 edited at 05 Mar 2021 21:19:28
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary code execution
Description
+ A security issue was found in Privoxy before version 3.0.32. An invalid pattern passed to pcre_compile() could lead to invalid memory accesses. Note that the obsolete PCRE code is scheduled to be removed before the 3.0.33 release. There has been a warning since 2008 already.
References
+ https://bugzilla.redhat.com/show_bug.cgi?id=1935974
+ https://www.privoxy.org/announce.txt
+ https://www.privoxy.org/gitweb/?p=privoxy.git;a=commitdiff;h=28512e5b62457f0ff6f2d72e3e5c9226b9e0203d
CVE-2021-20276 created at 05 Mar 2021 21:03:53