CVE-2016-5387
Description
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
Fedora Affected 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 24 | Affected | โ |
| 23 | Affected | โ |
SUSE Affected 3 releases
| Version | Status | Fixed in |
|---|---|---|
| 42.1 | Affected | โ |
| 13.2 | Affected | โ |
| โ | Affected | โ |
Ubuntu Affected 4 releases
| Version | Status | Fixed in |
|---|---|---|
| 16.04 | Affected | โ |
| 15.10 | Affected | โ |
| 14.04 | Affected | โ |
| 12.04 | Affected | โ |
Debian Mixed 6 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 2.4.23-2 |
| sid | Fixed | 2.4.23-2 |
| forky | Fixed | 2.4.23-2 |
| bullseye | Fixed | 2.4.23-2 |
| bookworm | Fixed | 2.4.23-2 |
| 8.0 | Affected | โ |
Red Hat Mixed 8 releases
| Version | Status | Fixed in |
|---|---|---|
| 7.7 | Affected | โ |
| 7.6 | Affected | โ |
| 7.5 | Affected | โ |
| 7.4 | Affected | โ |
| 7.3 | Affected | โ |
| 7.2 | Affected | โ |
| 7.0 | Not affected | โ |
| 6.0 | Not affected | โ |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| apache | http_server | {"startIncluding":"2.2.0","endIncluding":"2.2.31"} | |
| hp | system_management_homepage | {"endIncluding":"7.5.5.0"} | |
| oracle | communications_user_data_repository | {"startIncluding":"10.0.0","endIncluding":"12.4"} | |
| oracle | enterprise_manager_ops_center | 12.2.2 | |
| oracle | enterprise_manager_ops_center | 12.3.2 | |
| redhat | jboss_web_server | 2.1.0 | |
| redhat | jboss_enterprise_web_server | 2.0.0 | |
| redhat | jboss_enterprise_web_server | 3.0.0 | |
| redhat | jboss_core_services | 1.0 | |
| apache | http_server | {"startIncluding":"2.4.1","endIncluding":"2.4.23"} | |
References
- https://security-tracker.debian.org/tracker/CVE-2016-5387
- http://lists.opensuse.org/opensuse-updates/2016-07/msg00059.html
- http://rhn.redhat.com/errata/RHSA-2016-1624.html
- http://rhn.redhat.com/errata/RHSA-2016-1625.html
- http://rhn.redhat.com/errata/RHSA-2016-1648.html
- http://rhn.redhat.com/errata/RHSA-2016-1649.html
- http://rhn.redhat.com/errata/RHSA-2016-1650.html
- http://www.debian.org/security/2016/dsa-3623
- http://www.kb.cert.org/vuls/id/797896
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.securityfocus.com/bid/91816
- http://www.securitytracker.com/id/1036330
- http://www.ubuntu.com/usn/USN-3038-1
- https://access.redhat.com/errata/RHSA-2016:1420
- https://access.redhat.com/errata/RHSA-2016:1421
- https://access.redhat.com/errata/RHSA-2016:1422
- https://access.redhat.com/errata/RHSA-2016:1635
- https://access.redhat.com/errata/RHSA-2016:1636
- https://access.redhat.com/errata/RHSA-2016:1851
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.