CVE-2013-2503
medium
CVSS v3
—
CVSS v2
5.8
VIR risk
6.8
Description
Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.
Predictions
Exploit likelihood
55%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-2503
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2013-2503.html
Exploits
Exploit-DB
- EDB-38377 · webapps · php
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | fixed | 3.0.21-1 |
| debian | bullseye | fixed | 3.0.21-1 |
| debian | forky | fixed | 3.0.21-1 |
| debian | sid | fixed | 3.0.21-1 |
| debian | trixie | fixed | 3.0.21-1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| privoxy | privoxy | {"endIncluding":"3.0.20"} | |
| privoxy | privoxy | 2.9.0 | |
| privoxy | privoxy | 2.9.1 | |
| privoxy | privoxy | 2.9.2 | |
| privoxy | privoxy | 2.9.3 | |
| privoxy | privoxy | 2.9.11 | |
| privoxy | privoxy | 2.9.12 | |
| privoxy | privoxy | 2.9.13 | |
| privoxy | privoxy | 2.9.14 | |
| privoxy | privoxy | 2.9.16 | |
| privoxy | privoxy | 2.9.18 | |
| privoxy | privoxy | 3.0 | |
| privoxy | privoxy | 3.0.2 | |
| privoxy | privoxy | 3.0.3 | |
| privoxy | privoxy | 3.0.5 | |
| privoxy | privoxy | 3.0.6 | |
| privoxy | privoxy | 3.0.7 | |
| privoxy | privoxy | 3.0.8 | |
| privoxy | privoxy | 3.0.9 | |
| privoxy | privoxy | 3.0.10 | |
| privoxy | privoxy | 3.0.11 | |
| privoxy | privoxy | 3.0.12 | |
| privoxy | privoxy | 3.0.13 | |
| privoxy | privoxy | 3.0.14 | |
| privoxy | privoxy | 3.0.15 | |
| privoxy | privoxy | 3.0.16 | |
| privoxy | privoxy | 3.0.17 | |
| privoxy | privoxy | 3.0.18 | |
| privoxy | privoxy | 3.0.19 | |
References
- https://www.suse.com/security/cve/CVE-2013-2503.html
- http://blog.c22.cc/2013/03/11/privoxy-proxy-authentication-credential-exposure-cve-2013-2503/
- http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/ChangeLog?revision=1.188&view=markup
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00118.html
- https://security-tracker.debian.org/tracker/CVE-2013-2503
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.