current/doc/webserver announce.txt,1.35,1.36

Fabian Keil <[email protected]>
Newsgroups gmane.comp.web.privoxy.cvs
Message-ID <[email protected]>
Update of /cvsroot/ijbswa/current/doc/webserver
In directory sfp-cvs-1.v30.ch3.sourceforge.com:/tmp/cvs-serv10105/doc/webserver

Modified Files:
	announce.txt 
Log Message:
Add CVEs for Privoxy 3.0.24


Index: announce.txt
===================================================================
RCS file: /cvsroot/ijbswa/current/doc/webserver/announce.txt,v
retrieving revision 1.35
retrieving revision 1.36
diff -C2 -d -r1.35 -r1.36
*** announce.txt	21 Jan 2016 15:57:16 -0000	1.35
--- announce.txt	22 Jan 2016 10:20:48 -0000	1.36
***************
*** 4,9 ****
  Privoxy 3.0.24 stable contains a couple of new features but is
  mainly a bug-fix release. Two of the fixed bugs are security issues
! (CVE requests pending) and may be used to remotely trigger crashes
! on platforms that carefully check memory accesses (most don't).
  
  --------------------------------------------------------------------
--- 4,9 ----
  Privoxy 3.0.24 stable contains a couple of new features but is
  mainly a bug-fix release. Two of the fixed bugs are security issues
! and may be used to remotely trigger crashes on platforms that
! carefully check memory accesses (most don't).
  
  --------------------------------------------------------------------
***************
*** 12,18 ****
  - Security fixes (denial of service):
    - Prevent invalid reads in case of corrupt chunk-encoded content.
!     Bug discovered with afl-fuzz and AddressSanitizer.
    - Remove empty Host headers in client requests.
!     Previously they would result in invalid reads.
      Bug discovered with afl-fuzz and AddressSanitizer.
  
--- 12,18 ----
  - Security fixes (denial of service):
    - Prevent invalid reads in case of corrupt chunk-encoded content.
!     CVE-2016-1982. Bug discovered with afl-fuzz and AddressSanitizer.
    - Remove empty Host headers in client requests.
!     Previously they would result in invalid reads. CVE-2016-1983.
      Bug discovered with afl-fuzz and AddressSanitizer.
  


------------------------------------------------------------------------------
Site24x7 APM Insight: Get Deep Visibility into Application Performance
APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month
Monitor end-to-end web transactions and take corrective actions now
Troubleshoot faster and improve end-user experience. Signup Now!
http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.