CVE-2013-2503
EPSS 3.5%
Description
Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.
How to fix CVE-2013-2503
To remediate CVE-2013-2503, upgrade the affected package to a fixed version below.
- Debian/privoxy—upgrade to 3.0.21-1 or later
Is CVE-2013-2503 being exploited?
Low — EPSS is 3.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.0.21-1