ISOMAN

CVE

CVE-2016-5386

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

Severity
HIGH
CVSS
8.1
Published
Modified

Linked Releases

References

  1. http://rhn.redhat.com/errata/RHSA-2016-1538.html
  2. http://www.kb.cert.org/vuls/id/797896
  3. http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
  4. http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
  5. https://bugzilla.redhat.com/show_bug.cgi?id=1353798
  6. https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us
  7. https://httpoxy.org/
  8. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WGHKKCFP4PLVSWQKCM3FJJPEWB5ZNTU/
  9. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OR52UXGM6RKSCWF3KQMVZGVZVJ3WEESJ/
  10. http://rhn.redhat.com/errata/RHSA-2016-1538.html
  11. http://www.kb.cert.org/vuls/id/797896
  12. http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
  13. http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
  14. https://bugzilla.redhat.com/show_bug.cgi?id=1353798
  15. https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us
  16. https://httpoxy.org/
  17. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WGHKKCFP4PLVSWQKCM3FJJPEWB5ZNTU/
  18. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OR52UXGM6RKSCWF3KQMVZGVZVJ3WEESJ/