LWN.net Logo

Fedora alert FEDORA-2013-3756 (privoxy)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 17 Update: privoxy-3.0.21-1.fc17
Date:  Fri, 22 Mar 2013 00:33:57 +0000
Message-ID:  <20130322003357.4761920FB4@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-3756 2013-03-12 22:35:49 -------------------------------------------------------------------------------- Name : privoxy Product : Fedora 17 Version : 3.0.21 Release : 1.fc17 URL : http://www.privoxy.org/ Summary : Privacy enhancing proxy Description : Privoxy is a web proxy with advanced filtering capabilities for protecting privacy, filtering web page content, managing cookies, controlling access, and removing ads, banners, pop-ups and other obnoxious Internet junk. Privoxy has a very flexible configuration and can be customized to suit individual needs and tastes. Privoxy has application for both stand-alone systems and multi-user networks. Privoxy is based on the Internet Junkbuster. -------------------------------------------------------------------------------- Update Information: Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2503 to the following vulnerability: Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code. References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2503 [2] http://blog.c22.cc/2013/03/11/privoxy-proxy-authenticatio... [3] http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/C... -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 12 2013 Jon Ciesla <limburgher@gmail.com> - 3.0.21-1 - 3.0.21, fix for CVE-2013-2503. * Mon Oct 1 2012 Jon Ciesla <limburgher@gmail.com> - 3.0.16-6.2 - Change ownership of binary and config to root. * Mon Oct 1 2012 Jon Ciesla <limburgher@gmail.com> - 3.0.16-6.1 - Allow execution by all users, BZ 849932. -------------------------------------------------------------------------------- References: [ 1 ] Bug #920645 - CVE-2013-2503 privoxy: Proxy-Authentication response spoofing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=920645 [ 2 ] Bug #920647 - CVE-2013-2503 privoxy: Proxy-Authentication response spoofing [epel-6] https://bugzilla.redhat.com/show_bug.cgi?id=920647 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update privoxy' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds