Back to Database
Status published
High
CVE-2016-1983
The client_host function in parsers.c in Privoxy before 3.0.24 allows...
Vulnerability Description
The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-1983
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.debian.org/security/2016/dsa-3460
- http://www.openwall.com/lists/oss-security/2016/01/22/3
- http://www.openwall.com/lists/oss-security/2016/01/21/4
- http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/parsers.c?r1=1.302&r2=1.303
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176492.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176475.html
- http://www.privoxy.org/announce.txt
More from privoxy
View All →CVE-2016-1982
The remove_chunked_transfer_coding function in filters.c in Privoxy before 3.0.24 allows...
High
7.5
CVE-2015-1380
jcc.c in Privoxy before 3.0.23 allows remote attackers to cause...
Medium
5
CVE-2015-1201
Privoxy before 3.0.22 allows remote attackers to cause a denial...
Medium
5
CVE-2015-1031
Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote attackers...
High
7.5
CVE-2015-1030
Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy...
Medium
5
Affected Vendor
privoxy
View all reports →Affected Software
privoxy
Vulnerable Versions:
0
Timeline
Official Publish:
January 27th, 2016
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.