Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:2115-1

Опубликовано: 19 авг. 2016
Источник: suse-cvrf

Описание

Security update for apache2-mod_fcgid

This update for apache2-mod_fcgid fixes the following issues:

  • CVE-2016-1000104 / CVE-2016-5387: A remote attacker could have set the HTTP_PROXY environment variable of CGI scripts (boo#988488)

Список пакетов

openSUSE Leap 42.1
apache2-mod_fcgid-2.3.9-7.1

Описание

A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.


Затронутые продукты
openSUSE Leap 42.1:apache2-mod_fcgid-2.3.9-7.1

Ссылки

Описание

The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.


Затронутые продукты
openSUSE Leap 42.1:apache2-mod_fcgid-2.3.9-7.1

Ссылки