LWN.net Logo

privoxy: proxy spoofing

Package(s):privoxy CVE #(s):CVE-2013-2503
Created:March 22, 2013 Updated:April 3, 2013
Description:

From the Fedora advisory:

Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.

Alerts:
Fedora FEDORA-2013-3756 2013-03-22
Fedora FEDORA-2013-3753 2013-03-22
openSUSE openSUSE-SU-2013:0564-1 2013-03-31
Mageia MGASA-2013-0103 2013-04-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds