| From: |
| Mageia Updates <buildsystem-daemon@mageia.org> |
| To: |
| updates-announce@ml.mageia.org |
| Subject: |
| [updates-announce] MGASA-2013-0103: privoxy-3.0.21-1.mga2 (2/core) |
| Date: |
| Tue, 2 Apr 2013 22:09:31 +0200 |
| Message-ID: |
| <20130402200931.GA6215@valstar.mageia.org> |
| Archive-link: |
| Article, Thread
|
MGASA-2013-0103
Date: April 2nd, 2013
Affected releases: 2
Media: Core
Description:
Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and
Proxy-Authorization headers in the client-server data stream, which
makes it easier for remote HTTP servers to spoof the intended proxy
ervice via a 407 (aka Proxy Authentication Required) HTTP status code.
(CVE-2013-2503)
Updated Packages:
i586:
privoxy-3.0.21-1.mga2.i586.rpm
privoxy-debug-3.0.21-1.mga2.i586.rpm
x86_64:
privoxy-3.0.21-1.mga2.x86_64.rpm
privoxy-debug-3.0.21-1.mga2.x86_64.rpm
SRPMS:
privoxy-3.0.21-1.mga2.src.rpm
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2503
https://groups.google.com/forum/?hl=en&fromgroups=#!t...
http://lists.fedoraproject.org/pipermail/package-announce...
https://bugs.mageia.org/show_bug.cgi?id=9335
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-...
(
Log in to post comments)