CVE-2016-5385
15Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 50%
probabilidade de exploração
50%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.
Produtos afetados
n/a · n/aReferências
http://lists.opensuse.org/opensuse-updates/2016-08/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1609.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1610.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1611.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1612.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1613.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1353794https://github.com/guzzle/guzzle/releases/tag/6.2.1https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_ushttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05333297https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722