First published: Mon Mar 11 2013(Updated: )
Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Privoxy Privoxy | <=3.0.20 | |
Privoxy Privoxy | =2.9.0-pre-alpha | |
Privoxy Privoxy | =2.9.1-pre-alpha | |
Privoxy Privoxy | =2.9.2-pre-alpha | |
Privoxy Privoxy | =2.9.3-pre-alpha | |
Privoxy Privoxy | =2.9.11-alpha | |
Privoxy Privoxy | =2.9.11-beta | |
Privoxy Privoxy | =2.9.11-pre-alpha | |
Privoxy Privoxy | =2.9.12-beta | |
Privoxy Privoxy | =2.9.13-beta | |
Privoxy Privoxy | =2.9.14-beta | |
Privoxy Privoxy | =2.9.16 | |
Privoxy Privoxy | =2.9.18 | |
Privoxy Privoxy | =3.0 | |
Privoxy Privoxy | =3.0.2 | |
Privoxy Privoxy | =3.0.3 | |
Privoxy Privoxy | =3.0.5-beta | |
Privoxy Privoxy | =3.0.6 | |
Privoxy Privoxy | =3.0.7-beta | |
Privoxy Privoxy | =3.0.8 | |
Privoxy Privoxy | =3.0.9-beta | |
Privoxy Privoxy | =3.0.10 | |
Privoxy Privoxy | =3.0.11 | |
Privoxy Privoxy | =3.0.12 | |
Privoxy Privoxy | =3.0.13-beta | |
Privoxy Privoxy | =3.0.14-beta | |
Privoxy Privoxy | =3.0.15-beta | |
Privoxy Privoxy | =3.0.16 | |
Privoxy Privoxy | =3.0.17 | |
Privoxy Privoxy | =3.0.18 | |
Privoxy Privoxy | =3.0.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.