stable

privoxy-3.0.21-1.el6

FEDORA-EPEL-2013-0632 created by limb 11 years ago for Fedora EPEL 6

Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2503 to the following vulnerability:

Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.

References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2503 [2] http://blog.c22.cc/2013/03/11/privoxy-proxy-authentication-credential-exposure-cve-2013-2503/ [3] http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/ChangeLog?revision=1.188&view=markup

This update has been submitted for testing by limb.

11 years ago

This update is currently being pushed to the Fedora EPEL 6 testing updates repository.

11 years ago

This update has been pushed to testing

11 years ago

This update has reached 14 days in testing and can be pushed to stable now if the maintainer wishes

11 years ago

This update has been submitted for stable by limb.

11 years ago

This update is currently being pushed to the Fedora EPEL 6 stable updates repository.

11 years ago

This update has been pushed to stable

11 years ago

Please login to add feedback.

Metadata
Type
security
Karma
0
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
11 years ago
in testing
11 years ago
in stable
11 years ago
BZ#920645 CVE-2013-2503 privoxy: Proxy-Authentication response spoofing [fedora-all]
0
0
BZ#920647 CVE-2013-2503 privoxy: Proxy-Authentication response spoofing [epel-6]
0
0

Automated Test Results