-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 07 Dec 2021 19:59:33 +0100 Source: privoxy Architecture: source Version: 3.0.32-2+deb11u1 Distribution: bullseye Urgency: medium Maintainer: Roland Rosenfeld <roland@debian.org> Changed-By: Roland Rosenfeld <roland@debian.org> Changes: privoxy (3.0.32-2+deb11u1) bullseye; urgency=medium . * 53_CVE-2021-44540: get_url_spec_param(): Free memory of compiled pattern spec before bailing (CVE-2021-44540). * 54_CVE-2021-44541: process_encrypted_request_headers(): Free header memory when failing to get the request destination (CVE-2021-44541). * 55_CVE-2021-44542: send_http_request(): Prevent memory leaks when handling errors (CVE-2021-44542). * 56_CVE-2021-44543: cgi_error_no_template(): Encode the template name to prevent XSS (CVE-2021-44543). Checksums-Sha1: 3aefdd7d2413950303239d861886c76b0b3b8c37 2384 privoxy_3.0.32-2+deb11u1.dsc 82ffee6b6f55eadb0231c66e443ae2707fef6d31 29716 privoxy_3.0.32-2+deb11u1.debian.tar.xz bc168f1e0e098f9e5a83a29d88a00dd96d34ae89 10265 privoxy_3.0.32-2+deb11u1_source.buildinfo Checksums-Sha256: 86fcf6df925c18184070ecf9f051f2f333a3e23b811efe3d0395c6d195d86018 2384 privoxy_3.0.32-2+deb11u1.dsc 9f3e1363f5dad1e15be79cc805c321a3b8a21de4509574de8b5ac3ecb406de7a 29716 privoxy_3.0.32-2+deb11u1.debian.tar.xz 0e6c39afd5ba2ae3b1d0cf0a9921923b3a7cc5c6e02a74d000bb67217ebd0cb3 10265 privoxy_3.0.32-2+deb11u1_source.buildinfo Files: 7ab4e242580019faf736ea9c5c60cb24 2384 web optional privoxy_3.0.32-2+deb11u1.dsc 9e54bdb57b5c5a52c72228e2fb19fc81 29716 web optional privoxy_3.0.32-2+deb11u1.debian.tar.xz 6be566a145699698a54e5cc0fc9d0cce 10265 web optional privoxy_3.0.32-2+deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEErC+9sQSUPYpEoCEdAnE7z8pUELIFAmGyGqQACgkQAnE7z8pU ELJxVg//X1300YGpkzuyJyhjrh5lIn/9m7WX74/d86QThOU6WcRnukb9eM62iWnO S3aYvp7ikJV5QzEsVFSrvsY4FCcz7wNducFMrexrNT64sl/TFMZNzqmeYb2ILrZT qiy2a/wVxKj2qJympbpAvrrxUlan3SivRiZx+n2flVQU3+Undi6vhprncENJ1UoK DLLKZMpa55egTXeQtxsK7zJUQqUnpG7jWvcWOwkrJtP7NZHKLsEQtpFO44rOy00T ZoGEWleT6DixZ5aeL5p3Zkjw29gsrmHt+/ABlKWdWIyDQtIpXbZbX8LZEtFxOl6Q MQ0w8HrmIDlVM0CcJQObeBgYAjnw8SScfeyLt2C3Kd9fmJRKxxdBVXMUjjD7faB9 yV1kIJGLKgw5beHJv1CTbyIZL/lKkvZQYUNPncO+xQkJE0riz8oQ0Yrd+4X/hyVy +69Qr6t6bKMgKyFvRY5W3/PVUe1EL5eqf63vmg0nWROkD18OkyTki/A5MFKjEhM1 2NXSIiiGClucgrcszeNi6tY/eJTPS6iA549Ym/q4sE1eG0OnXCb4LqRzfUMuNxq0 JGSPoYZgYETPtxDJ/qUhVlmbr1J4AadLeFIzVP8n59WvrTTLqjE8ot+rHonm/HCh khtkpCcfIsS9+j3VSNU3NR4tn1UHVPTIDN37/Q2O6e6iIvr3SKE= =vB76 -----END PGP SIGNATURE-----