Privoxy 4.2.0 has been released with security fixes for two flaws in the privacy-focused non-caching web proxy, including a bug in parse_chunk_size() triggered by malformed chunk sizes in HTTP/1.0 Chunked Transfer Encoding handling and a flaw in ssl_send_certificate_error() caused by incorrect data-length processing that could lead to an integer overflow. The project said CVE identifiers were still pending at the time of publication, and the release also updates dependency handling by dropping support for mbedtls 2.x and OpenSSL 2.0.
The release also expands HTTPS inspection capabilities, including support for elliptic-curve certificates using SN_X9_62_prime256v1 in some cases, adds a new --enable-acl-debugging option, and improves web-based action-file editing, logging, and other web interface behavior. Privoxy, distributed under GPLv2+ for Linux and Windows, is used for privacy enhancement, ad blocking, cookie control, header modification, and web content filtering.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Privoxy 4.2.0 was released with new and improved features including HTTPS inspection enhancements, ACL debugging support, and web interface updates. The release also fixed security issues in parse_chunk_size() and ssl_send_certificate_error(), with CVE identifiers noted as pending.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.