[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.5] Go: sets environmental variable based on user supplied Proxy request header (CVE-2016-5386)

ID: oval:org.secpod.oval:def:1800516Date: (C)2018-03-28   (M)2023-12-20
Class: PATCHFamily: unix




Many software projects and vendors have implemented support for the Proxy request header in their respective CGI implementations and languages by creating the HTTP_PROXY environmental variable based on the header value. When this variable is used any outgoing requests generated in turn from the attackers original request can be redirected to an attacker controlled proxy. This allows attackers to view potentially sensitive information, reply with malformed data, or to hold connections open causing a potential denial of service.

Platform:
Alpine Linux 3.5
Product:
go
Reference:
5931
CVE-2016-5386
CVE    1
CVE-2016-5386
CPE    3
cpe:/a:golang:go
cpe:/o:alpinelinux:alpine_linux:3.5
cpe:/a:golang:go:1.6

© SecPod Technologies