CVE-2016-1000108

Published: 10 December 2019

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

Priority

Low

CVSS 3 base score: 6.1

Status

Package Release Status
yaws
Launchpad, Ubuntu, Debian
Upstream Needed

Ubuntu 21.04 (Hirsute Hippo) Not vulnerable
(2.0.3-2)
Ubuntu 20.10 (Groovy Gorilla) Not vulnerable
(2.0.3-2)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(2.0.3-2)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(2.0.3-2)
Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(end of standard support, was needed)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was needed)