← Back

CVE-2013-2503

nvd nist
Published: Mar 11, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.

Affected (31)

Products: Privoxy: Privoxy
1 product
Privoxy
Configuration A
31 vulnerable
Vulnerable SoftwareAffected Versions
Privoxy
Up to 3.0.20
Version 2.9.0 pre-alpha
Version 2.9.11 alpha
Version 2.9.11 beta
Version 2.9.11 pre-alpha
Version 2.9.12 beta
Version 2.9.13 beta
Version 2.9.14 beta
Version 2.9.16
Version 2.9.18
Version 2.9.1 pre-alpha
Version 2.9.2 pre-alpha
Version 2.9.3 pre-alpha
Version 3.0.10
Version 3.0.11
Version 3.0.12
Version 3.0.13 beta
Version 3.0.14 beta
Version 3.0.15 beta
Version 3.0.16
Version 3.0.17
Version 3.0.18
Version 3.0.19
Version 3.0.2
Version 3.0.3
Version 3.0.5 beta
Version 3.0.6
Version 3.0.7 beta
Version 3.0.8
Version 3.0.9 beta
Version 3.0

Timeline

No history available yet.