Login
Newsletter
Werbung

Sicherheit: Mangelnde Eingabeprüfung in Privoxy
Aktuelle Meldungen Distributionen
Name: Mangelnde Eingabeprüfung in Privoxy
ID: FEDORA-2013-3756
Distribution: Fedora
Plattformen: Fedora 17
Datum: Fr, 22. März 2013, 08:02
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2503
Applikationen: Privoxy

Originalnachricht

Name        : privoxy
Product : Fedora 17
Version : 3.0.21
Release : 1.fc17
URL : http://www.privoxy.org/
Summary : Privacy enhancing proxy
Description :
Privoxy is a web proxy with advanced filtering capabilities for
protecting privacy, filtering web page content, managing cookies,
controlling access, and removing ads, banners, pop-ups and other
obnoxious Internet junk. Privoxy has a very flexible configuration and
can be customized to suit individual needs and tastes. Privoxy has application
for both stand-alone systems and multi-user networks.

Privoxy is based on the Internet Junkbuster.

-------------------------------------------------------------------------------
-
Update Information:

Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2503 to
the following vulnerability:

Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and
Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.

References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2503
[2] privoxy-proxy-authentication-credential-exposure-cve-2013-2503
[3] ChangeLog?revision=1.188&view=markup
-------------------------------------------------------------------------------
-
ChangeLog:

* Tue Mar 12 2013 Jon Ciesla <limburgher@gmail.com> - 3.0.21-1
- 3.0.21, fix for CVE-2013-2503.
* Mon Oct 1 2012 Jon Ciesla <limburgher@gmail.com> - 3.0.16-6.2
- Change ownership of binary and config to root.
* Mon Oct 1 2012 Jon Ciesla <limburgher@gmail.com> - 3.0.16-6.1
- Allow execution by all users, BZ 849932.
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #920645 - CVE-2013-2503 privoxy: Proxy-Authentication response
spoofing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=920645
[ 2 ] Bug #920647 - CVE-2013-2503 privoxy: Proxy-Authentication response
spoofing [epel-6]
https://bugzilla.redhat.com/show_bug.cgi?id=920647
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update privoxy' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung