httpoxy

Differences between revisions 2 and 3
Revision 2 as of 2016-07-18 18:31:23
Size: 1284
Editor: mdeslaur
Comment:
Revision 3 as of 2025-04-17 11:55:16
Size: 1364
Editor: lucistanescu
Comment: Migrated to main website
Deletions are marked like this. Additions are marked like this.
Line 1: Line 1:
#DEPRECATED
#REFRESH 10 https://ubuntu.com/security/vulnerabilities/httpoxy

httpoxy CGI application vulnerability

httpoxy is a vulnerability in CGI environments related to handling the Proxy header:

  • RFC3875 puts the HTTP Proxy header from requests into environment variables as HTTP_PROXY
  • HTTP_PROXY in a common environment variable used to configure a proxy server

Resolution

This issue will be fixed in pending security updates. Some of the packages affected by this issue are:

Mitigation

The Ubuntu Security team encourages everyone to apply the mitigations listed on the httpoxy information page.

Timeline

  • 2016 Jul 18: The httpoxy disclosure team discloses their findings

httpoxy CGI application vulnerability

httpoxy is a vulnerability in CGI environments related to handling the Proxy header:

  • RFC3875 puts the HTTP Proxy header from requests into environment variables as HTTP_PROXY
  • HTTP_PROXY in a common environment variable used to configure a proxy server

Resolution

This issue will be fixed in pending security updates. Some of the packages affected by this issue are:

Mitigation

The Ubuntu Security team encourages everyone to apply the mitigations listed on the httpoxy information page.

Timeline

  • 2016 Jul 18: The httpoxy disclosure team discloses their findings

SecurityTeam/KnowledgeBase/httpoxy (last edited 2025-04-17 11:55:16 by lucistanescu)