CVE-2016-1000111

Published: 18 July 2016

Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

Priority

Low

CVSS 3 base score: 5.3

Status

Package Release Status
twisted
Launchpad, Ubuntu, Debian
Upstream Needed

Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(17.9.0-1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (16.0.0-1ubuntu0.2)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (13.2.0-1ubuntu1.2)
twisted-py3
Launchpad, Ubuntu, Debian
Upstream Needed

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was needed)