PublicDateAtUSN: 2016-07-18 14:00:00 Candidate: CVE-2016-5387 CRD: 2016-07-18 14:00:00 PublicDate: 2016-07-19 02:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5387 https://httpoxy.org/ https://www.apache.org/security/asf-httpoxy-response.txt https://ubuntu.com/security/notices/USN-3038-1 Description: The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_apache2: upstream_apache2: needs-triage precise_apache2: released (2.2.22-1ubuntu1.11) trusty_apache2: released (2.4.7-1ubuntu4.13) trusty/esm_apache2: released (2.4.7-1ubuntu4.13) vivid/stable-phone-overlay_apache2: DNE vivid/ubuntu-core_apache2: DNE wily_apache2: released (2.4.12-2ubuntu2.1) xenial_apache2: released (2.4.18-2ubuntu3.1) esm-infra/xenial_apache2: released (2.4.18-2ubuntu3.1) devel_apache2: released (2.4.18-2ubuntu4)