Описание
Security update for apache2-mod_fcgid
This update for apache2-mod_fcgid fixes the following issues:
- CVE-2016-1000104 / CVE-2016-5387: A remote attacker could have set the HTTP_PROXY environment variable of CGI scripts (boo#988488)
Список пакетов
openSUSE Leap 42.1
apache2-mod_fcgid-2.3.9-7.1
Ссылки
- E-Mail link for openSUSE-SU-2016:2115-1
- SUSE Security Ratings
Описание
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
Затронутые продукты
openSUSE Leap 42.1:apache2-mod_fcgid-2.3.9-7.1
Ссылки
- CVE-2016-1000104
- SUSE Bug 988492
Описание
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
Затронутые продукты
openSUSE Leap 42.1:apache2-mod_fcgid-2.3.9-7.1
Ссылки
- CVE-2016-5387
- SUSE Bug 988484
- SUSE Bug 988486
- SUSE Bug 988487
- SUSE Bug 988488
- SUSE Bug 988489
- SUSE Bug 988491
- SUSE Bug 988492
- SUSE Bug 989125
- SUSE Bug 989174
- SUSE Bug 989684