suse · CVE-2016-1000107

Quick triage

Priority: medium Published: 2021-05-30 13:49:50 UTC Updated: 2026-04-18 15:49:56 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-1000107 severity moderate: SUSE including 20 source package names (erlang-28.1.1-1.1, erlang-debugger-28.1.1-1.1, …), 20 product×package rows across 1 product lines (openSUSE Tumbleweed): Fixed 20.

Description:

inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

cvelogic Threat Intelligence