Vulnerability Bulletins |
DSA-3623 apache2 - security update |
|
| Affected software | Debian |
|
Scott Geary of VendHQ discovered that the Apache HTTPD server used thevalue of the Proxy header from HTTP requests to initialize theHTTP_PROXY environment variable for CGI scripts, which in turn wasincorrectly used by certain HTTP client implementations to configure theproxy for outgoing HTTP requests. A remote attacker could possibly usethis flaw to redirect HTTP requests performed by a CGI script to anattacker-controlled proxy via a malicious HTTP request. More info: https://www.debian.org/security/2016/dsa-3623 |
|






