Bug 27678 - privoxy 3.0.29 fixes security issues (CVE-2020-35502, CVE-2021-20209, CVE-2021-2021[0-5])
Summary: privoxy 3.0.29 fixes security issues (CVE-2020-35502, CVE-2021-20209, CVE-202...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-11-28 22:14 CET by David Walser
Modified: 2021-02-03 17:22 CET (History)
5 users (show)

See Also:
Source RPM: privoxy-3.0.28-1.mga7.src.rpm
CVE:
Status comment:


Attachments
Privoxy 3.0.29 ChangeLog (14.59 KB, text/plain)
2020-11-28 22:14 CET, David Walser
Details

Description David Walser 2020-11-28 22:14:12 CET
Privoxy 3.0.29 has been released today (November 28).  The website hasn't been updated, but the ChangeLog is available at SourceForge.  It lists 8 security fixes (no CVEs).

Mageia 7 is also affected.
Comment 1 David Walser 2020-11-28 22:14:44 CET
Created attachment 12025 [details]
Privoxy 3.0.29 ChangeLog
David Walser 2020-11-28 22:14:53 CET

Whiteboard: (none) => MGA7TOO

Comment 2 Aurelien Oudelet 2020-11-29 11:58:38 CET
Hi, thanks for reporting this bug.
Assigned to the package maintainer.

(Please set the status to 'assigned' if you are working on it)

CC: (none) => ouaurelien
Assignee: bugsquad => cjw

Comment 3 David Walser 2020-11-29 16:31:01 CET
privoxy-3.0.29-1.mga8 uploaded for Cauldron by Stig-Ørjan.

Version: Cauldron => 7
Whiteboard: MGA7TOO => (none)
CC: (none) => smelror

Comment 4 Stig-Ørjan Smelror 2020-11-29 19:19:20 CET
Advisory
========

Privoxy has been updated to version 3.0.29 to fix 8 security issues.

References
==========
https://sourceforge.net/projects/ijbswa/files/Sources/3.0.29%20%28stable%29/announce.txt

Files
=====

Uploaded to core/updates_testing

privoxy-3.0.29-1.mga7

from privoxy-3.0.29-1.mga7.src.rpm

Assignee: cjw => smelror

Comment 5 David Walser 2020-11-29 19:21:19 CET
Thanks.

Hopefully the version on the website will be updated by time we push this:
http://www.privoxy.org/announce.txt

Assignee: smelror => qa-bugs

Comment 6 David Walser 2020-11-30 18:35:02 CET
Security fixes posted here, use this for References rather than URL in Comment 4:
https://www.openwall.com/lists/oss-security/2020/11/29/1
Comment 7 Herman Viaene 2020-12-04 16:23:23 CET
MGA7-64 MATE on Peaq C1011
No installation issues.
# systemctl start privoxy

# systemctl -l status privoxy
● privoxy.service - Privacy enhancing HTTP Proxy
   Loaded: loaded (/usr/lib/systemd/system/privoxy.service; disabled; vendor preset: disabled)
   Active: active (running) since Fri 2020-12-04 16:07:13 CET; 34s ago
  Process: 16753 ExecStart=/usr/sbin/privoxy --pidfile /run/privoxy.pid --user daemon.daemon /etc/privoxy/config (code=exited, status=0/SUCCESS)
 Main PID: 16754 (privoxy)
    Tasks: 1 (limit: 2288)
   Memory: 1.3M
   CGroup: /system.slice/privoxy.service
           └─16754 /usr/sbin/privoxy --pidfile /run/privoxy.pid --user daemon.daemon /etc/privoxy/config

Dec 04 16:07:12 mach6.hviaene.thuis systemd[1]: Starting Privacy enhancing HTTP Proxy...
Dec 04 16:07:13 mach6.hviaene.thuis systemd[1]: Started Privacy enhancing HTTP Proxy
Ref bug 14892 for testing. Change firefox network settings to proxy localhost port 8118 and open this port in firewall.
Browse to a non-existent host, e.g. http://www.n.zz/
And I see a privoxy page saying "No such domain". OK

Browse to http://ad.example.com/
And I see a privoxy page saying "Request for blocked URL" with reason "Host matches generic block pattern".

Browse to www.google.be, blocked as well, anyone wondering???
OK for me.

Whiteboard: (none) => MGA7-64-OK
CC: (none) => herman.viaene

Comment 8 Thomas Andrews 2020-12-04 23:27:44 CET
Validating. Advisory in Comment 4.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Comment 9 Aurelien Oudelet 2020-12-05 17:20:04 CET
Advisory pushed to SVN.

Keywords: (none) => advisory
Source RPM: privoxy-3.0.28-3.mga8.src.rpm => privoxy-3.0.28-1.mga7.src.rpm

Comment 10 Mageia Robot 2020-12-05 20:48:11 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0447.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 11 David Walser 2021-02-03 17:22:36 CET
CVEs have been assigned for this update:
https://www.openwall.com/lists/oss-security/2021/02/03/3

Summary: privoxy 3.0.29 fixes security issues => privoxy 3.0.29 fixes security issues (CVE-2020-35502, CVE-2021-20209, CVE-2021-2021[0-5])


Note You need to log in before you can comment on or make changes to this bug.