Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 461526 (CVE-2013-2503) - <net-proxy/privoxy-3.0.21: Proxy-Authentication response spoofing (CVE-2013-2503)
Summary: <net-proxy/privoxy-3.0.21: Proxy-Authentication response spoofing (CVE-2013-2...
Status: RESOLVED FIXED
Alias: CVE-2013-2503
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-03-12 14:29 UTC by Agostino Sarubbo
Modified: 2013-03-24 20:21 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-03-12 14:29:29 UTC
From ${URL} :

Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2503 to the following 
vulnerability:

Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers 
in the client-server data stream, which makes it easier for remote HTTP servers to spoof the 
intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.

References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2503
[2] http://blog.c22.cc/2013/03/11/privoxy-proxy-authentication-credential-exposure-cve-2013-2503/
[3] http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/ChangeLog?revision=1.188&view=markup
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2013-03-14 12:38:44 UTC
net-proxy, is =net-proxy/privoxy-3.0.21 ready for stabilization?
Comment 2 Tom Wijsman (TomWij) (RETIRED) gentoo-dev 2013-03-14 12:47:00 UTC
This was just added yesterday so this has not been tested thoroughly yet. We might want to wait a minimal amount of days to see if no bugs arise, let's wait until the start of next week at least before stabilizing this version.
Comment 3 Sean Amoss (RETIRED) gentoo-dev Security 2013-03-14 13:07:15 UTC
(In reply to comment #2)
> This was just added yesterday so this has not been tested thoroughly yet. We
> might want to wait a minimal amount of days to see if no bugs arise, let's
> wait until the start of next week at least before stabilizing this version.

Thanks, Tom. We will follow-up the beginning of next week then.
Comment 4 Agostino Sarubbo gentoo-dev 2013-03-17 19:09:47 UTC
With the ok from the maintainer on irc:

Arches, please test and mark stable:
=net-proxy/privoxy-3.0.21
Target keywords : "alpha amd64 arm ppc ppc64 sparc x86"
Comment 5 Agostino Sarubbo gentoo-dev 2013-03-17 19:11:25 UTC
amd64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2013-03-17 19:11:46 UTC
x86 stable
Comment 7 Agostino Sarubbo gentoo-dev 2013-03-17 19:12:08 UTC
ppc stable
Comment 8 Agostino Sarubbo gentoo-dev 2013-03-17 19:12:29 UTC
ppc64 stable
Comment 9 Agostino Sarubbo gentoo-dev 2013-03-17 19:16:24 UTC
arm stable
Comment 10 Agostino Sarubbo gentoo-dev 2013-03-17 19:16:44 UTC
alpha stable
Comment 11 Agostino Sarubbo gentoo-dev 2013-03-17 19:17:02 UTC
sparc stable
Comment 12 Agostino Sarubbo gentoo-dev 2013-03-17 19:22:26 UTC
Old version has been removed, please vote.
Comment 13 Sean Amoss (RETIRED) gentoo-dev Security 2013-03-19 21:17:25 UTC
GLSA vote: no
Comment 14 GLSAMaker/CVETool Bot gentoo-dev 2013-03-21 18:53:51 UTC
CVE-2013-2503 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2503):
  Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and
  Proxy-Authorization headers in the client-server data stream, which makes it
  easier for remote HTTP servers to spoof the intended proxy service via a 407
  (aka Proxy Authentication Required) HTTP status code.
Comment 15 Tobias Heinlein (RETIRED) gentoo-dev 2013-03-24 20:21:49 UTC
NO too, closing.