[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2016-5386 -- golang, golang-1.6

ID: oval:org.secpod.oval:def:1900842Date: (C)2019-03-05   (M)2023-12-20
Class: VULNERABILITYFamily: unix




The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application"s outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
golang
golang-1.6
Reference:
CVE-2016-5386
CVE    1
CVE-2016-5386
CPE    4
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/a:golang:golang1.6
cpe:/o:ubuntu:ubuntu_linux:14.04
cpe:/a:golang:golang
...

© SecPod Technologies