Lucene search

K
f5F5F5:K17296065
HistoryNov 28, 2022 - 12:00 a.m.

K17296065 : Apache mod_userdir vulnerability CVE-2016-4975

2022-11-2800:00:00
my.f5.com
18
apache
mod_userdir
vulnerability
http response splitting
cve-2016-4975
apache http server

6.5 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.6%

Security Advisory Description

Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the “Location” or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31). (CVE-2016-4975)

Impact

There is no impact; F5 products are not affected by this vulnerability.