cbcvebase.
CVE-2013-2503
published 2013-03-11

CVE-2013-2503: Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for…

PriorityP336medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EXPLOIT
EPSS
4.63%
90.6th percentile
Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianprivoxy< privoxy 3.0.21-1 (bookworm)privoxy 3.0.21-1 (bookworm)
privoxyprivoxy<= 3.0.20
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy
privoxyprivoxy

CVSS provenance

nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.