Candidate: CVE-2016-4694 PublicDate: 2016-09-25 10:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4694 http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html http://lists.apple.com/archives/security-announce/2016/Sep/msg00009.html https://support.apple.com/HT207170 https://support.apple.com/HT207171 Description: The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue, a related issue to CVE-2016-5387. Ubuntu-Description: Notes: mdeslaur> this is probably an apple-specific CVE for the same issue as mdeslaur> CVE-2016-5387, marking as not-affected Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N [9.1 CRITICAL] Patches_apache2: upstream_apache2: not-affected precise_apache2: not-affected trusty_apache2: not-affected trusty/esm_apache2: not-affected vivid/stable-phone-overlay_apache2: DNE vivid/ubuntu-core_apache2: DNE xenial_apache2: not-affected esm-infra/xenial_apache2: not-affected devel_apache2: not-affected