Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-1000107

Опубликовано: 10 дек. 2019
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 5.8
CVSS3: 6.1

Описание

inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

РелизСтатусПримечание
artful

ignored

devel

ignored

esm-infra-legacy/trusty

ignored

trusty was ignored
esm-infra-legacy/xenial

ignored

esm-infra/xenial

ignored

precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

ignored

trusty/esm

ignored

end of ESM support, was ignored [trusty was ignored]
upstream

needs-triage

Показывать по

EPSS

Процентиль: 70%
0.01428
Низкий

5.8 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
redhat
больше 6 лет назад

inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 6.1
nvd
больше 6 лет назад

inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 6.1
debian
больше 6 лет назад

inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1 ...

CVSS3: 6.1
github
около 4 лет назад

inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

EPSS

Процентиль: 70%
0.01428
Низкий

5.8 Medium

CVSS2

6.1 Medium

CVSS3