[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

PHP - (bulletinjul2017)

ID: oval:org.secpod.oval:def:2101298Date: (C)2019-12-30   (M)2024-04-17
Class: PATCHFamily: unix




PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application"s outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv("HTTP_PROXY") call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.

Platform:
Sun Solaris 11
Product:
web/php-56
web/php-56/extension/php-xdebug
web/php-56/extension/php-suhosin-extension
Reference:
bulletinjul2017
CVE-2016-5385
CVE-2013-6501
CVE-2015-4021
CVE-2015-4022
CVE-2015-4025
CVE-2016-6288
CVE-2016-6289
CVE-2016-6291
CVE-2016-6292
CVE-2016-6293
CVE-2016-6294
CVE-2016-6295
CVE-2016-6296
CVE-2016-6297
CVE    14
CVE-2016-6294
CVE-2016-6293
CVE-2016-6292
CVE-2016-6295
...
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies