Lucene search

K
redhatRedHatRHSA-2016:1421
HistoryJul 18, 2016 - 12:00 a.m.

(RHSA-2016:1421) Important: httpd security update

2016-07-1800:00:00
access.redhat.com
30

0.2 Low

EPSS

Percentile

96.4%

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and
extensible web server.

Security Fix(es):

  • It was discovered that httpd used the value of the Proxy header from HTTP
    requests to initialize the HTTP_PROXY environment variable for CGI scripts,
    which in turn was incorrectly used by certain HTTP client implementations to
    configure the proxy for outgoing HTTP requests. A remote attacker could possibly
    use this flaw to redirect HTTP requests performed by a CGI script to an
    attacker-controlled proxy via a malicious HTTP request. (CVE-2016-5387)

Note: After this update, httpd will no longer pass the value of the Proxy
request header to scripts via the HTTP_PROXY environment variable.

Red Hat would like to thank Scott Geary (VendHQ) for reporting this issue.