UBUNTU-CVE-2013-2503

Source
https://ubuntu.com/security/CVE-2013-2503
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-2503.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2013-2503
Upstream
Withdrawn
2025-07-18T16:42:52Z
Published
2013-03-11T17:55:00Z
Modified
2025-07-16T08:10:44.109773Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.

References

Affected packages

Ubuntu:14.04:LTS / privoxy

Package

Name
privoxy
Purl
pkg:deb/ubuntu/privoxy@3.0.21-2?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.21-2

Affected versions

3.*
3.0.21-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "privoxy",
            "binary_version": "3.0.21-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-2503.json"