CVE-2016-5386
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.22% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- fedoraproject/fedora · oracle/linux · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · golang/go
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2016-1538.htmlThird Party Advisory
- http://www.kb.cert.org/vuls/id/797896Third Party Advisory, US Government Resource
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1353798Issue Tracking, Third Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_usThird Party Advisory
- https://httpoxy.org/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WGHKKCFP4PLVSWQKCM3FJJPEWB5ZNTU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OR52UXGM6RKSCWF3KQMVZGVZVJ3WEESJ/
- http://rhn.redhat.com/errata/RHSA-2016-1538.htmlThird Party Advisory
- http://www.kb.cert.org/vuls/id/797896Third Party Advisory, US Government Resource
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1353798Issue Tracking, Third Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_usThird Party Advisory
- https://httpoxy.org/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WGHKKCFP4PLVSWQKCM3FJJPEWB5ZNTU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OR52UXGM6RKSCWF3KQMVZGVZVJ3WEESJ/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.