Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1133

Опубликовано: 16 янв. 2016
Источник: debian
EPSS Низкий

Описание

CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URI.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
h2onot-affectedpackage

Примечания

  • https://github.com/h2o/h2o/issues/682

  • https://github.com/h2o/h2o/issues/684

  • https://github.com/h2o/h2o/pull/684

EPSS

Процентиль: 59%
0.00386
Низкий

Связанные уязвимости

CVSS3: 3.7
nvd
около 10 лет назад

CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URI.

CVSS3: 3.7
github
больше 3 лет назад

CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URI.

EPSS

Процентиль: 59%
0.00386
Низкий