Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade privoxy | Aug 30, 2017 | Mar 11, 2013 |
| Debian | — | Upgrade privoxy | Jul 30, 2024 | Mar 11, 2013 |
| Freebsd | — | Upgrade privoxy | Dec 10, 2025 | Jan 26, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 11, 2013 |
| Suse | — | Upgrade privoxy-debuginfoUpgrade privoxyUpgrade privoxy-debugsourceUpgrade privoxy-doc | Dec 12, 2013 | Mar 11, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub