privoxy.git
8 years agoUpdate INSTALL
Fabian Keil [Sun, 17 Jan 2016 14:32:49 +0000 (14:32 +0000)]
Update INSTALL

8 years agoUpdate README
Fabian Keil [Sun, 17 Jan 2016 14:32:40 +0000 (14:32 +0000)]
Update README

8 years agoUpdate AUTHORS
Fabian Keil [Sun, 17 Jan 2016 14:32:30 +0000 (14:32 +0000)]
Update AUTHORS

8 years agoBump p-version in SGML sources
Fabian Keil [Sun, 17 Jan 2016 14:32:19 +0000 (14:32 +0000)]
Bump p-version in SGML sources

8 years agoFix compiler warnings
Fabian Keil [Sun, 17 Jan 2016 14:31:59 +0000 (14:31 +0000)]
Fix compiler warnings

8 years agoFix a compiler warning when building without zlib support
Fabian Keil [Sun, 17 Jan 2016 14:31:47 +0000 (14:31 +0000)]
Fix a compiler warning when building without zlib support

8 years agoImport ChangeLog
Fabian Keil [Sun, 17 Jan 2016 14:31:33 +0000 (14:31 +0000)]
Import ChangeLog

8 years agoUpdate announcement for Privoxy 3.0.24 stable
Fabian Keil [Sun, 17 Jan 2016 14:31:21 +0000 (14:31 +0000)]
Update announcement for Privoxy 3.0.24 stable

8 years agoAdd ChangeLog for 3.0.24 stable
Fabian Keil [Sun, 17 Jan 2016 14:30:54 +0000 (14:30 +0000)]
Add ChangeLog for 3.0.24 stable

8 years agoBump copyright year
Fabian Keil [Sun, 17 Jan 2016 14:30:38 +0000 (14:30 +0000)]
Bump copyright year

8 years agoBump copyright year
Fabian Keil [Sat, 16 Jan 2016 12:33:45 +0000 (12:33 +0000)]
Bump copyright year

8 years agoDeclare 3.0.24 'stable'
Fabian Keil [Sat, 16 Jan 2016 12:33:16 +0000 (12:33 +0000)]
Declare 3.0.24 'stable'

8 years agoRemove non-standard Proxy-Agent headers in HTTP snipplets
Fabian Keil [Sat, 16 Jan 2016 12:33:03 +0000 (12:33 +0000)]
Remove non-standard Proxy-Agent headers in HTTP snipplets

They serve no real purpose and the fact that the headers
included the Privoxy version made testing inconvient.

8 years agoget_destination_from_headers(): Merge two log messages into one
Fabian Keil [Sat, 16 Jan 2016 12:32:18 +0000 (12:32 +0000)]
get_destination_from_headers(): Merge two log messages into one

8 years agoget_destination_from_headers(): Remove comment about code duplication
Fabian Keil [Sat, 16 Jan 2016 12:31:40 +0000 (12:31 +0000)]
get_destination_from_headers(): Remove comment about code duplication

While there's similar code elsewhere, it's not exactly the same.

8 years agoDocument forward-webserver
Fabian Keil [Sat, 16 Jan 2016 12:30:58 +0000 (12:30 +0000)]
Document forward-webserver

8 years agoIntroduce the new forwarding type 'forward-webserver'
Fabian Keil [Sat, 16 Jan 2016 12:30:43 +0000 (12:30 +0000)]
Introduce the new forwarding type 'forward-webserver'

Currently it is only supported by the forward-override{}
action and there's no config directive with the same
name.

The forwarding type is similar to 'forward', but the
request line only contains the path instead of the
complete URL.

This makes it more convenient to use Privoxy to make
existing websites available as onion services as well.

Many websites serve content with hardcoded URLs and
can't be easily adjusted to change the domain based
on the one used by the client.

Putting Privoxy between Tor and the webserver (or an stunnel
that forwards to the webserver) allows to rewrite headers and
content to make client and server happy at the same time.

8 years agoExtend comment explaining SOCKS_NONE
Fabian Keil [Sat, 16 Jan 2016 12:30:28 +0000 (12:30 +0000)]
Extend comment explaining SOCKS_NONE

8 years agoNote that someone is currently working on updating the CGI templates
Fabian Keil [Sat, 16 Jan 2016 12:30:05 +0000 (12:30 +0000)]
Note that someone is currently working on updating the CGI templates

8 years agoNote donor interest for #16, #144 and #145
Fabian Keil [Sat, 16 Jan 2016 12:29:51 +0000 (12:29 +0000)]
Note donor interest for #16, #144 and #145

8 years agoAdd Gregory Seidman as contributor
Fabian Keil [Sat, 16 Jan 2016 12:29:40 +0000 (12:29 +0000)]
Add Gregory Seidman as contributor

8 years agoload_one_actions_file(): Prevent invalid read if the buffer is too short
Fabian Keil [Sat, 16 Jan 2016 12:29:30 +0000 (12:29 +0000)]
load_one_actions_file(): Prevent invalid read if the buffer is too short

Found with afl-fuzz and AddressSanitizer.

8 years agoremove_chunked_transfer_coding(): Reject invalid input sooner
Fabian Keil [Sat, 16 Jan 2016 12:29:17 +0000 (12:29 +0000)]
remove_chunked_transfer_coding(): Reject invalid input sooner

Prevents invalid reads in case of corrupt input.
Bug discovered with alf-fuzz and ASAN.

8 years agoclient_host(): Remove empty host headers
Fabian Keil [Sat, 16 Jan 2016 12:29:00 +0000 (12:29 +0000)]
client_host(): Remove empty host headers

Previously they would result in invalid reads and crashes
when compiled with AddressSanitizer. Bug found with afl-fuzz.

8 years agopcre: Fix invalid reads in internal and outdated pcre code
Fabian Keil [Sat, 16 Jan 2016 12:28:43 +0000 (12:28 +0000)]
pcre: Fix invalid reads in internal and outdated pcre code

8 years agoDisable filter{banners-by-size} for .black-mosquito.org/
Fabian Keil [Sat, 16 Jan 2016 12:28:21 +0000 (12:28 +0000)]
Disable filter{banners-by-size} for .black-mosquito.org/

8 years agoDisable fast-redirects for disqus.com/
Fabian Keil [Sat, 16 Jan 2016 12:28:09 +0000 (12:28 +0000)]
Disable fast-redirects for disqus.com/

8 years agouagen: Update OS data for FreeBSD
Fabian Keil [Sat, 16 Jan 2016 12:27:56 +0000 (12:27 +0000)]
uagen: Update OS data for FreeBSD

alpha is no longer supported.

8 years agoFix the documented type of the forward-override{} action
Fabian Keil [Mon, 28 Dec 2015 18:56:36 +0000 (18:56 +0000)]
Fix the documented type of the forward-override{} action

... which is obviously 'parameterized'.

8 years agoCorrectly document the action type for a bunch of "multi-value" actions
Fabian Keil [Mon, 28 Dec 2015 18:56:19 +0000 (18:56 +0000)]
Correctly document the action type for a bunch of "multi-value" actions

... that were incorrectly documented to be "parameterized".

Reported by Gregory Seidman on ijbswa-users@.

8 years agoAdd Robert Klemme as contributor (donor)
Fabian Keil [Mon, 28 Dec 2015 18:56:05 +0000 (18:56 +0000)]
Add Robert Klemme as contributor (donor)

8 years agoCheck requests more carefully before serving them forcefully
Fabian Keil [Mon, 28 Dec 2015 18:55:49 +0000 (18:55 +0000)]
Check requests more carefully before serving them forcefully

... when blocks aren't enforced.

Privoxy always adds the force token at the beginning
of the path, but would previously accept it anywhere
in the request line.

This could result in requests being served that should
be blocked. For example in case of pages that were
loaded with force and contained JavaScript to create
additionally requests that embed the origin URL
(thus inheriting the force prefix).

The bug is not considered a security issue and the
fix does not make it harder for remote sites to
intentionally circumvent blocks if Privoxy isn't
configured to enforce them.

Fixes #1695 reported by Korda.

8 years agoFix a typo in #146
Fabian Keil [Sun, 27 Dec 2015 16:41:17 +0000 (16:41 +0000)]
Fix a typo in #146

8 years agoBlock a bunch of criteo domains
Fabian Keil [Sun, 27 Dec 2015 16:40:54 +0000 (16:40 +0000)]
Block a bunch of criteo domains

Reported by Black Rider.

8 years agoBlock abs.proxistore.com/abe/
Fabian Keil [Sun, 27 Dec 2015 16:40:40 +0000 (16:40 +0000)]
Block abs.proxistore.com/abe/

Reported by Black Rider.

8 years agoFix a regression test
Fabian Keil [Sun, 27 Dec 2015 16:40:20 +0000 (16:40 +0000)]
Fix a regression test

The intent was to verify that the URL is blocked and the keyword for
this is "Blocked URL" which does not depend on the currently active
"Sticky Actions" which may change in the future.

8 years agoAdd missing word in #143
Fabian Keil [Sun, 27 Dec 2015 13:32:02 +0000 (13:32 +0000)]
Add missing word in #143

8 years agoAdd Korda as contributor
Fabian Keil [Sun, 27 Dec 2015 13:31:48 +0000 (13:31 +0000)]
Add Korda as contributor

8 years agoAdd Guybrush Threepwood as contributor
Fabian Keil [Sun, 27 Dec 2015 13:31:36 +0000 (13:31 +0000)]
Add Guybrush Threepwood as contributor

8 years agoAdd Pak Chan as contributor
Fabian Keil [Sun, 27 Dec 2015 13:31:25 +0000 (13:31 +0000)]
Add Pak Chan as contributor

8 years agoAdd Rustam Abdullaev as contributor
Fabian Keil [Sun, 27 Dec 2015 13:31:15 +0000 (13:31 +0000)]
Add Rustam Abdullaev as contributor

8 years agoAdd #144-#146: Allow to pre-define tags that are set for clients that want them
Fabian Keil [Sun, 27 Dec 2015 12:56:33 +0000 (12:56 +0000)]
Add #144-#146: Allow to pre-define tags that are set for clients that want them

8 years agoAdd #143: Add support OpenBSD's pledge feature
Fabian Keil [Sun, 27 Dec 2015 12:56:04 +0000 (12:56 +0000)]
Add #143: Add support OpenBSD's pledge feature

8 years agoclient_host_adder(): Reject the request if the destination host is unknown
Fabian Keil [Sun, 27 Dec 2015 12:54:12 +0000 (12:54 +0000)]
client_host_adder(): Reject the request if the destination host is unknown

Previously the request would fail later on.
While at it, use a less silly log message.

8 years agoFix build with mingw x86_64
Fabian Keil [Sun, 27 Dec 2015 12:53:54 +0000 (12:53 +0000)]
Fix build with mingw x86_64

Submitted by Rustam Abdullaev in #135.

8 years agoacl_addr(): Properly parse acl directives with ports when compiled with HAVE_RFC2553
Fabian Keil [Sun, 27 Dec 2015 12:53:39 +0000 (12:53 +0000)]
acl_addr(): Properly parse acl directives with ports when compiled with HAVE_RFC2553

Previously the port wasn't removed from the host and in case of
'permit-access 127.0.0.1 example.org:80' Privoxy would try (and fail)
to resolve "example.org:80" instead of example.org.

Reported by Pak Chan on ijbswa-users@.

8 years agoGNUmakefile.in: Remove incomplete config-file-alt target
Fabian Keil [Sun, 27 Dec 2015 12:50:57 +0000 (12:50 +0000)]
GNUmakefile.in: Remove incomplete config-file-alt target

It's not needed and unlikely to get completed any time soon.

8 years agoAdd parse_numeric_value()
Fabian Keil [Sun, 27 Dec 2015 12:50:42 +0000 (12:50 +0000)]
Add parse_numeric_value()

... and use it to reject config directives with invalid
values more reliably.

8 years agoget_destination_from_headers(): Additionally update the request line in proxy format
Fabian Keil [Sun, 27 Dec 2015 12:49:29 +0000 (12:49 +0000)]
get_destination_from_headers(): Additionally update the request line in proxy format

This makes rewriting intercepted requests more convenient.

Previously it was expected to fail unless $hostport
was being used, but rewrites of intercepted requests
without $hostport failed "the wrong way" and would
result in an out-of-memory message (vanilla host patterns)
or a crash (extended host patterns).

Reported by "Guybrish Threepwood" in #1694.

8 years agoget_destination_from_headers(): Remove dead code
Fabian Keil [Sun, 27 Dec 2015 12:48:59 +0000 (12:48 +0000)]
get_destination_from_headers(): Remove dead code

8 years agohost_matches(): Assert that the host pointer isn't NULL
Fabian Keil [Sun, 27 Dec 2015 12:47:17 +0000 (12:47 +0000)]
host_matches(): Assert that the host pointer isn't NULL

8 years agoFix comment typos
Fabian Keil [Sun, 27 Dec 2015 12:46:46 +0000 (12:46 +0000)]
Fix comment typos

8 years agoexecute_external_filter(): Assert that the buffer for the filter output is large...
Fabian Keil [Sun, 27 Dec 2015 12:46:34 +0000 (12:46 +0000)]
execute_external_filter(): Assert that the buffer for the filter output is large enough

8 years agopcrs_strerror(): Include the error code for unknown errors
Fabian Keil [Sun, 27 Dec 2015 12:45:46 +0000 (12:45 +0000)]
pcrs_strerror(): Include the error code for unknown errors

While the approach (static buffer) is somewhat racy,
it's unlikely to matter in practice.

8 years agowebserver: Update with recent changes
Fabian Keil [Fri, 6 Nov 2015 13:38:55 +0000 (13:38 +0000)]
webserver: Update with recent changes

The update has been done manually as I currently
have no working docbook setup.

8 years agowebsite: Add Ian's mirror to the download section
Fabian Keil [Fri, 6 Nov 2015 13:38:38 +0000 (13:38 +0000)]
website: Add Ian's mirror to the download section

8 years agocgi_show_status(): Stop treating files called standard.action special
Fabian Keil [Fri, 6 Nov 2015 13:38:13 +0000 (13:38 +0000)]
cgi_show_status(): Stop treating files called standard.action special

... and allow to edit them just like any other action file.

Nowadays the official "standards" are part of default.action
and there's no obvious reason to disallow editing them through
the cgi editor anyway (if the user decided that the lack of
authentication isn't an issue in her environment).

8 years agoBlock requests for "resources.infolinks.com/"
Fabian Keil [Fri, 6 Nov 2015 13:37:55 +0000 (13:37 +0000)]
Block requests for "resources.infolinks.com/"

Reported by "Black Rider" on ijbswa-users@.

8 years agoaccept_connection(): Enable socket lingering for the correct socket
Fabian Keil [Fri, 6 Nov 2015 13:37:35 +0000 (13:37 +0000)]
accept_connection(): Enable socket lingering for the correct socket

Previously we repeatedly enabled it for the listen socket
instead of for the accepted socket. The bug was found by
code inspection and did not cause any (reported) issues.

8 years agoaccept_connection(): Set NO_DELAY flag for the accepting socket
Fabian Keil [Fri, 6 Nov 2015 13:35:24 +0000 (13:35 +0000)]
accept_connection(): Set NO_DELAY flag for the accepting socket

This significantly reduces the latency if the operating
system is not configured to set the flag by default.

For Windows the unnecessary delay has been reported
to be ~200ms while on ElectroBSD it's still 100ms.

Reported by Johan Sintorn in #894.

8 years agoFactor out set_no_delay_flag() to reduce code duplication
Fabian Keil [Fri, 6 Nov 2015 13:34:56 +0000 (13:34 +0000)]
Factor out set_no_delay_flag() to reduce code duplication

While at it, log an error message if setting the flag
fails and let the compiler emit a warning if Privoxy
is compiled on a platform where the function is a nop.

9 years agoAdd #142: Remove or update the "internal" pcre version
Fabian Keil [Tue, 25 Aug 2015 11:35:00 +0000 (11:35 +0000)]
Add #142: Remove or update the "internal" pcre version

9 years agoBetter late than never: bump version to 3.0.24 UNRELEASED
Fabian Keil [Tue, 25 Aug 2015 11:34:10 +0000 (11:34 +0000)]
Better late than never: bump version to 3.0.24 UNRELEASED

9 years agoAdd Yang Xia as contributor
Fabian Keil [Fri, 21 Aug 2015 10:59:07 +0000 (10:59 +0000)]
Add Yang Xia as contributor

9 years agoexecute_external_filter(): Actually fix the buffer scaling
Fabian Keil [Fri, 21 Aug 2015 10:58:53 +0000 (10:58 +0000)]
execute_external_filter(): Actually fix the buffer scaling

The previous commit was about as wrong as the code it
"fixed" and could still result in a buffer that wasn't
large enough to hold all the output from the external filter.

Submitted by Yang Xia in #892.

9 years agoAdd Jonathan McKenzie as contributor
Fabian Keil [Wed, 12 Aug 2015 10:41:26 +0000 (10:41 +0000)]
Add Jonathan McKenzie as contributor

9 years agoAdd Joel Verhagen and Jarry Xu as contributors
Fabian Keil [Wed, 12 Aug 2015 10:41:16 +0000 (10:41 +0000)]
Add Joel Verhagen and Jarry Xu as contributors

9 years agoFAQ: Explicitly point fingers at ASUS
Fabian Keil [Wed, 12 Aug 2015 10:40:42 +0000 (10:40 +0000)]
FAQ: Explicitly point fingers at ASUS

.. as an example of a company that has been reported
to force malware based on Privoxy upon its customers.

9 years agoWinMain: Use the correct function to close the event handle
Fabian Keil [Wed, 12 Aug 2015 10:39:16 +0000 (10:39 +0000)]
WinMain: Use the correct function to close the event handle

According to Microsoft's documentation DeleteObject() is
used to delete a "logical pen, brush, font, bitmap, region,
or palette" while CloseHandle() is supposed to be used
for the handle returned by CreateEvent():
https://msdn.microsoft.com/en-us/library/windows/desktop/dd183539%28v=vs.85%29.aspx
https://msdn.microsoft.com/en-us/library/windows/desktop/ms682396%28v=vs.85%29.aspx
https://msdn.microsoft.com/en-us/library/windows/desktop/ms724211%28v=vs.85%29.aspx

It's conceivable that this commit fixes a tiny memory leak,
but then again maybe not as DeleteObject() is apparently full
of magic:
http://blogs.msdn.com/b/oldnewthing/archive/2013/03/06/10399678.aspx

Reported by Jarry Xu in #891.

9 years agoFAQ: Fix spelling of affect
Fabian Keil [Wed, 12 Aug 2015 10:38:45 +0000 (10:38 +0000)]
FAQ: Fix spelling of affect

9 years ago#132: Note some work in progress
Fabian Keil [Wed, 12 Aug 2015 10:38:16 +0000 (10:38 +0000)]
#132: Note some work in progress

9 years agoload_config(): In case of invalid forward-socks5(t) directives, use the correct direc...
Fabian Keil [Wed, 12 Aug 2015 10:38:02 +0000 (10:38 +0000)]
load_config(): In case of invalid forward-socks5(t) directives, use the correct directive name

Previously the error messages referred to forward-socks4t failures.

Reported by Joel Verhagen in #889.

9 years agoAdd #141: Port Privoxy to CloudABI
Fabian Keil [Wed, 12 Aug 2015 10:37:44 +0000 (10:37 +0000)]
Add #141: Port Privoxy to CloudABI

9 years agoUnblock klikki.fi/adv/
Fabian Keil [Wed, 12 Aug 2015 10:37:26 +0000 (10:37 +0000)]
Unblock klikki.fi/adv/

9 years agotranslate_socks5_error(): Improve SOCKS5_REQUEST_HOST_UNREACHABLE translation
Fabian Keil [Wed, 12 Aug 2015 10:37:11 +0000 (10:37 +0000)]
translate_socks5_error(): Improve SOCKS5_REQUEST_HOST_UNREACHABLE translation

... to make it more obvious that it's the destination
host that is unreachable and not the host running the
socks server.

9 years agomalloc_or_die(): Catch and prevent attempted zero-size allocations
Fabian Keil [Wed, 12 Aug 2015 10:34:38 +0000 (10:34 +0000)]
malloc_or_die(): Catch and prevent attempted zero-size allocations

9 years agoexecute_external_filter(): Don't rely on undefined malloc() behaviour
Fabian Keil [Wed, 12 Aug 2015 10:34:21 +0000 (10:34 +0000)]
execute_external_filter(): Don't rely on undefined malloc() behaviour

... and fix the read buffer scaling for initial sizes below READ_LENGTH.

Could fix the crash reported by Jonathan McKenzie on ijbswa-users@

9 years agodocbook2man-spec.pl: Update the inserted man page banner
Fabian Keil [Wed, 12 Aug 2015 10:33:56 +0000 (10:33 +0000)]
docbook2man-spec.pl: Update the inserted man page banner

.. to make it more obvious that the script is part of Privoxy's source tarball.

Remove suggestion that bug reports should be reported to the original author
as the referenced address is no longer useful thanks to a domain squatter.

9 years agoDisable filter{banners-by-size} for .plasmaservice.de/
Fabian Keil [Wed, 12 Aug 2015 10:33:32 +0000 (10:33 +0000)]
Disable filter{banners-by-size} for .plasmaservice.de/

9 years agoget_actions(): Detect and reject parameters for parameter-less actions
Fabian Keil [Wed, 12 Aug 2015 10:33:13 +0000 (10:33 +0000)]
get_actions(): Detect and reject parameters for parameter-less actions

Previously they were silently ignored.

9 years agoIncrease socks5_connect()'s optimism
Fabian Keil [Thu, 18 Jun 2015 15:26:40 +0000 (15:26 +0000)]
Increase socks5_connect()'s optimism

... and let it send the request body optimistically as well.

It's not that complicated and, more importantly, previously
the request body wasn't guaranteed to be sent at all.

Should fix #1686 reported by Peter Müller and G4JC.

9 years agoRegenerated docs with CVEs for 3.0.23 and bumped copyright
Fabian Keil [Sun, 29 Mar 2015 17:22:36 +0000 (17:22 +0000)]
Regenerated docs with CVEs for 3.0.23 and bumped copyright

9 years agoBump copyright
Fabian Keil [Sun, 29 Mar 2015 17:22:20 +0000 (17:22 +0000)]
Bump copyright

9 years agoAdd CVEs for 3.0.23 stable
Fabian Keil [Sun, 29 Mar 2015 17:22:05 +0000 (17:22 +0000)]
Add CVEs for 3.0.23 stable

9 years agoBump copyright
Fabian Keil [Fri, 27 Mar 2015 12:42:13 +0000 (12:42 +0000)]
Bump copyright

9 years agoAdd CVEs for Privoxy 3.0.23
Fabian Keil [Fri, 27 Mar 2015 12:41:57 +0000 (12:41 +0000)]
Add CVEs for Privoxy 3.0.23

9 years agolisten_loop(): Add number of active threads to a couple of log messages
Fabian Keil [Fri, 27 Mar 2015 12:40:08 +0000 (12:40 +0000)]
listen_loop(): Add number of active threads to a couple of log messages

9 years agodecompress_iob(): Refine the log message emitted when the iob is too small
Fabian Keil [Fri, 27 Mar 2015 12:39:44 +0000 (12:39 +0000)]
decompress_iob(): Refine the log message emitted when the iob is too small

9 years agoUnblock .deutschlandradiokultur.de/
Fabian Keil [Sat, 21 Feb 2015 18:56:34 +0000 (18:56 +0000)]
Unblock .deutschlandradiokultur.de/

Reported by u302320 in #924.

9 years agoAdd two fast-redirect exceptions for yandex.ru
Fabian Keil [Sat, 21 Feb 2015 18:55:53 +0000 (18:55 +0000)]
Add two fast-redirect exceptions for yandex.ru

9 years agoImport last-minute changes
Fabian Keil [Mon, 26 Jan 2015 11:26:16 +0000 (11:26 +0000)]
Import last-minute changes

9 years agoFix contributor name
Fabian Keil [Mon, 26 Jan 2015 11:25:45 +0000 (11:25 +0000)]
Fix contributor name

9 years agoRegenerate docs for Privoxy 3.0.23 stable
Fabian Keil [Sat, 24 Jan 2015 16:44:43 +0000 (16:44 +0000)]
Regenerate docs for Privoxy 3.0.23 stable

9 years agoRegenerate config file for Privoxy 3.0.23
Fabian Keil [Sat, 24 Jan 2015 16:44:20 +0000 (16:44 +0000)]
Regenerate config file for Privoxy 3.0.23

9 years agoImport changelog for Privoxy 3.0.23
Fabian Keil [Sat, 24 Jan 2015 16:44:08 +0000 (16:44 +0000)]
Import changelog for Privoxy 3.0.23

9 years agoAdd CVEs for Privoxy 3.0.22 stable
Fabian Keil [Sat, 24 Jan 2015 16:43:45 +0000 (16:43 +0000)]
Add CVEs for Privoxy 3.0.22 stable

9 years agoAdd changes for 3.0.23 stable
Fabian Keil [Sat, 24 Jan 2015 16:43:34 +0000 (16:43 +0000)]
Add changes for 3.0.23 stable

9 years agoDeclare 3.0.23 'stable'
Fabian Keil [Sat, 24 Jan 2015 16:43:21 +0000 (16:43 +0000)]
Declare 3.0.23 'stable'

9 years agoAdd Basil Hussain as contributor
Fabian Keil [Sat, 24 Jan 2015 16:43:11 +0000 (16:43 +0000)]
Add Basil Hussain as contributor

9 years agoPrevent parse errors after failing to deliver a client request with body
Fabian Keil [Sat, 24 Jan 2015 16:42:57 +0000 (16:42 +0000)]
Prevent parse errors after failing to deliver a client request with body

For now we err on the safe side and simply throw all the following
requests under the bus, even if no client body has been buffered.
A compliant client will repeat the dropped requests on an untainted
connection.

The proper fix is to discard the no longer needed client body
in the buffer (if there is one) and to continue parsing the
bytes that follow. This is less trivial and will have to wait
until the next release.

Reported by Basil Hussain.