Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy before 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests that are rejected because the socket limit is reached.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade privoxy | Aug 30, 2017 | Feb 10, 2015 |
| Debian | — | Upgrade privoxy | Jul 30, 2024 | Jan 20, 2015 |
| Freebsd | — | Upgrade privoxy | Dec 10, 2025 | Jan 26, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 28, 2014 |
| Suse | — | Upgrade privoxy | Dec 9, 2016 | Jan 20, 2015 |
| Ubuntu | — | Upgrade privoxy | Nov 19, 2024 | Jan 20, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub