suse · CVE-2016-5385

Quick triage

Priority: medium Published: 2021-05-30 13:43:43 UTC Updated: 2025-05-17 23:57:23 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-5385 severity moderate: SUSE including 348 source package names (apache2-mod_php5-5.5.14-68.1, apache2-mod_php53, …), 560 product×package rows across 20 product lines (SUSE Enterprise Storage 7.1, SUSE Liberty Linux 7, … (20 product lines)): Known Not Affected 419, Fixed 141.

Description:

PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.

cvelogic Threat Intelligence