{"id":"UBUNTU-CVE-2013-2503","details":"Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.","modified":"2025-07-16T08:10:44.109773Z","published":"2013-03-11T17:55:00Z","withdrawn":"2025-07-18T16:42:52Z","upstream":["CVE-2013-2503"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2013-2503"},{"type":"REPORT","url":"http://blog.c22.cc/2013/03/11/privoxy-proxy-authentication-credential-exposure-cve-2013-2503/"},{"type":"REPORT","url":"http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/ChangeLog?revision=1.188&view=markup"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2013-2503"}],"affected":[{"package":{"name":"privoxy","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/privoxy@3.0.21-2?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.21-2"}]}],"versions":["3.0.21-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"privoxy","binary_version":"3.0.21-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-2503.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}