| Summary: | privoxy 3.0.33 fixes security issues (CVE-2021-4454[0-3]) | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, cjw, herman.viaene, sysadmin-bugs |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | privoxy-3.0.32-2.mga9.src.rpm | CVE: | |
| Status comment: | |||
| Attachments: | Privoxy 3.0.33 ChangeLog | ||
|
Description
David Walser
2021-12-08 17:32:16 CET
Created attachment 13027 [details]
Privoxy 3.0.33 ChangeLog
David Walser
2021-12-08 17:33:03 CET
Whiteboard:
(none) =>
MGA8TOO Announcement/ChangeLog is now posted at the URL in Comment 0. Christiaan uploaded the 3.0.33 I committed and patched 3.0.32 for Mageia 8. privoxy-3.0.32-1.1.mga8 from privoxy-3.0.32-1.1.mga8.src.rpm Whiteboard:
MGA8TOO =>
(none) MGA8-64 Plasma on Lenovo B50 in Dutch No installation issues Followed procedure from bug 28281 Comment 10 # systemctl start privoxy [root@mach5 ~]# systemctl -l status privoxy ● privoxy.service - Privacy enhancing HTTP Proxy Loaded: loaded (/usr/lib/systemd/system/privoxy.service; disabled; vendor preset: disabled) Active: active (running) since Tue 2021-12-14 14:51:57 CET; 3s ago Process: 5168 ExecStart=/usr/sbin/privoxy --pidfile /run/privoxy.pid --user daemon.daemon /etc/privoxy/config (code=exited, status=0/SUCCESS) Main PID: 5169 (privoxy) Tasks: 1 (limit: 9396) Memory: 1.1M CPU: 9ms CGroup: /system.slice/privoxy.service └─5169 /usr/sbin/privoxy --pidfile /run/privoxy.pid --user daemon.daemon /etc/privoxy/config dec 14 14:51:56 mach5.hviaene.thuis systemd[1]: Starting Privacy enhancing HTTP Proxy... dec 14 14:51:57 mach5.hviaene.thuis systemd[1]: Started Privacy enhancing HTTP Proxy. Opened port 8118/tcp on firewall, changed firefox network settings to proxy localhost port 8118 and and set "Use this proxy for https" on. Refreshed open tabs in Firefox: allk OK Browse to a non-existent host, e.g. http://www.n.zz/ And I see a privoxy page saying "No such domain". OK Browse to http://ad.example.com/ And I see a privoxy page saying "Request for blocked URL" with reason "Host matches generic block pattern". Revert Firefox network to system-wide, stop privoxy, all active tabs in Firefox OK Good to go. CC:
(none) =>
herman.viaene Validating. Keywords:
(none) =>
validated_update
Thomas Backlund
2021-12-19 16:15:33 CET
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0570.html Status:
NEW =>
RESOLVED |