CVE-2016-5387
Description
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | forky | fixed | 2.4.23-2 |
| debian | sid | fixed | 2.4.23-2 |
| debian | trixie | fixed | 2.4.23-2 |
| debian | bookworm | fixed | 2.4.23-2 |
| debian | bullseye | fixed | 2.4.23-2 |
| sles | affected | | |
| fedora | 23 | affected | |
| fedora | 24 | affected | |
| rhel | 6.0 | not-affected | |
| rhel | 7.0 | not-affected | |
| rhel | 7.2 | affected | |
| rhel | 7.3 | affected | |
| rhel | 7.4 | affected | |
| rhel | 7.5 | affected | |
| rhel | 7.6 | affected | |
| rhel | 7.7 | affected | |
| suse | 42.1 | affected | |
| suse | 13.2 | affected | |
| debian | 8.0 | affected | |
| ubuntu | 12.04 | affected | |
| ubuntu | 14.04 | affected | |
| ubuntu | 15.10 | affected | |
| ubuntu | 16.04 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| apache | http_server | {"startIncluding":"2.2.0","endIncluding":"2.2.31"} | |
| hp | system_management_homepage | {"endIncluding":"7.5.5.0"} | |
| oracle | communications_user_data_repository | {"startIncluding":"10.0.0","endIncluding":"12.4"} | |
| oracle | enterprise_manager_ops_center | 12.2.2 | |
| oracle | enterprise_manager_ops_center | 12.3.2 | |
| redhat | jboss_web_server | 2.1.0 | |
| redhat | jboss_enterprise_web_server | 2.0.0 | |
| redhat | jboss_enterprise_web_server | 3.0.0 | |
| redhat | jboss_core_services | 1.0 | |
| apache | http_server | {"startIncluding":"2.4.1","endIncluding":"2.4.23"} | |
References
- https://security-tracker.debian.org/tracker/CVE-2016-5387
- http://lists.opensuse.org/opensuse-updates/2016-07/msg00059.html
- http://rhn.redhat.com/errata/RHSA-2016-1624.html
- http://rhn.redhat.com/errata/RHSA-2016-1625.html
- http://rhn.redhat.com/errata/RHSA-2016-1648.html
- http://rhn.redhat.com/errata/RHSA-2016-1649.html
- http://rhn.redhat.com/errata/RHSA-2016-1650.html
- http://www.debian.org/security/2016/dsa-3623
- http://www.kb.cert.org/vuls/id/797896
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.securityfocus.com/bid/91816
- http://www.securitytracker.com/id/1036330
- http://www.ubuntu.com/usn/USN-3038-1
- https://access.redhat.com/errata/RHSA-2016:1420
- https://access.redhat.com/errata/RHSA-2016:1421
- https://access.redhat.com/errata/RHSA-2016:1422
- https://access.redhat.com/errata/RHSA-2016:1635
- https://access.redhat.com/errata/RHSA-2016:1636
- https://access.redhat.com/errata/RHSA-2016:1851
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.