content:en_us:announcements_cve_cve-2016-5387

CVE 2016-5387

/** * This is the notes section. CVE documents should ONLY be created by employees of ClearCenter with the authority to make statements on behalf of the company. If you have content that would be useful to the statement, please contact ClearCenter. */

'The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an “httpoxy” issue. NOTE: the vendor states “This mitigation has been assigned the identifier CVE-2016-5387”; in other words, this is not a CVE ID for a vulnerability.'

ClearCenter response

This issue affects ClearOS 7 and ClearOS 6.

Short response

This issue was fixed in the backported fixes of versions of:

  • httpd version 2.4.6-40 and later in ClearOS 7
  • webconfig-httpd version 2.4.6-40 and later in ClearOS 7
  • httpd version 2.2.15-54 or later in ClearOS 6
  • webconfig-httpd version 2.2.15-54 or later in ClearOS 6

Long response

This issue was fixed during the maintenance cycle of ClearOS 7 and 6. ClearOS systems that are up to date do not suffer from this vulnerability. Some vulnerability scanning software may report this bug because their only method for determining the issue is to check the http version number since the exploit requires specific web configurations and has not other means for testing vulnerability. In ClearOS, version numbers stay consistent through the product's life-cycle and will produce a false positive on this issue if the testing software considers only the http version and not the ClearOS patch level.

Resolution

If you are running ClearOS 6 or 7, please ensure that you are running the latest updates:

yum update

You may also validate your version by running:

rpm -qi httpd

You should validate that you are running:

ClearOS 7
  • httpd version 2.4.6-40 or later
  • webconfig-httpd version 2.4.6-40 or later
ClearOS 6
  • httpd version 2.2.15-54 or later
  • webconfig-httpd version 2.2.15-54 or later
content/en_us/announcements_cve_cve-2016-5387.txt · Last modified: 2018/10/01 04:11 by dloper

Page Tools