Candidate: CVE-2016-1000107 PublicDate: 2019-12-10 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1000107 https://httpoxy.org/ Description: inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. Ubuntu-Description: Notes: mdeslaur> we will not be fixing this in erlang, marking as ignored Bugs: https://bugs.erlang.org/browse/ERL-198 Priority: negligible Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_erlang: upstream_erlang: needs-triage precise_erlang: ignored (reached end-of-life) precise/esm_erlang: DNE (precise was needed) trusty_erlang: ignored trusty/esm_erlang: ignored (trusty was ignored) vivid/stable-phone-overlay_erlang: DNE vivid/ubuntu-core_erlang: DNE wily_erlang: ignored (reached end-of-life) xenial_erlang: ignored esm-infra/xenial_erlang: ignored yakkety_erlang: ignored (reached end-of-life) zesty_erlang: ignored artful_erlang: ignored devel_erlang: ignored