← Back

CVE-2016-5385

nvd nist
Published: Jul 19, 2016Modified: May 6, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.

Affected (20)

Show all products
3 products
Enterprise Manager Ops Center
Linux
1 product
Fedora
2 products
System Management Homepage
1 product
Php
3 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Workstation
1 product
Debian Linux
1 product
Leap
1 product
Drupal
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 10.0.0
Version 10.0.1
Version 12.0.0
Oracle
Version 12.2.2
Version 12.3.2
Oracle
Version 6
Version 7
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 23
Version 24
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.09
Running on/withPlatform Versions
Hp
Storeever Msl6480 Tape Library
All versions
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 7.5.5.0
Configuration E
3 vulnerable
Vulnerable SoftwareAffected Versions
Php
From 5.5.0 to 5.5.38
From 5.6.0 to 5.6.24
From 7.0.0 to 7.0.8
Configuration F
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.0
Version 6.0
Version 6.0
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration H
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 42.1
Configuration I
1 vulnerable
Vulnerable SoftwareAffected Versions
From 8.0.0 to 8.1.7

References (50)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Broken LinkThird Party Advisory
Source: secalert@redhat.com
Broken LinkThird Party Advisory
Source: secalert@redhat.com
Broken LinkThird Party Advisory
Source: secalert@redhat.com
Broken LinkThird Party Advisory
Source: secalert@redhat.com
Broken LinkThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryUS Government Resource
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Issue TrackingThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
Release NotesThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.