From: Fabian Keil
$Id: developer-manual.sgml,v 2.59 2016/01/17
- 14:32:18 fabiankeil Exp $
$Id: developer-manual.sgml,v 2.60 2016/01/21
+ 15:55:48 fabiankeil Exp $
$Id: faq.sgml,v 2.110 2016/01/17 14:32:19 fabiankeil +
$Id: faq.sgml,v 2.111 2016/01/21 15:55:49 fabiankeil
Exp $
$Id: user-manual.sgml,v 2.198 2016/01/17 14:32:19 +
$Id: user-manual.sgml,v 2.199 2016/01/21 15:55:49
fabiankeil Exp $
Privoxy 3.0.24 stable contains a couple of new features but is mainly a bug-fix release. Two of the fixed - bugs are security issues (CVE requests pending) and may be used to - remotely trigger crashes on platforms that carefully check memory - accesses (most don't).
+ bugs are security issues and may be used to remotely trigger crashes on + platforms that carefully check memory accesses (most don't).Prevent invalid reads in case of corrupt chunk-encoded - content. Bug discovered with afl-fuzz and AddressSanitizer.
+ content. CVE-2016-1982. Bug discovered with afl-fuzz and + AddressSanitizer.Remove empty Host headers in client requests. Previously they - would result in invalid reads. Bug discovered with afl-fuzz and - AddressSanitizer.
+ would result in invalid reads. CVE-2016-1983. Bug discovered with + afl-fuzz and AddressSanitizer.Fixed crashes when executing external filters on platforms - like Mac OS X. Reported by Jonathan McKenzie on ijbswa-users@.
+ like Mac OS X. Reported by Jonathan McKenzie on + ijbswa-users@.