8.1

CVE-2016-5385

PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.

Data is provided by the National Vulnerability Database (NVD)
OracleLinux Version6 Update-
OracleLinux Version7 Update-
FedoraprojectFedora Version23
FedoraprojectFedora Version24
HpSystem Management Homepage Version <= 7.5.5.0
PhpPhp Version >= 5.5.0 < 5.5.38
PhpPhp Version >= 5.6.0 < 5.6.24
PhpPhp Version >= 7.0.0 <= 7.0.8
DebianDebian Linux Version8.0
OpensuseLeap Version42.1
DrupalDrupal Version >= 8.0.0 < 8.1.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 84.16% 0.993
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

http://rhn.redhat.com/errata/RHSA-2016-1609.html
Third Party Advisory
Broken Link
http://rhn.redhat.com/errata/RHSA-2016-1610.html
Third Party Advisory
Broken Link
http://rhn.redhat.com/errata/RHSA-2016-1611.html
Third Party Advisory
Broken Link
http://rhn.redhat.com/errata/RHSA-2016-1612.html
Third Party Advisory
Broken Link
http://rhn.redhat.com/errata/RHSA-2016-1613.html
Third Party Advisory
Broken Link
http://www.kb.cert.org/vuls/id/797896
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/91821
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1036335
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1353794
Third Party Advisory
VDB Entry
Issue Tracking
https://github.com/guzzle/guzzle/releases/tag/6.2.1
Third Party Advisory
Release Notes
https://httpoxy.org/
Third Party Advisory