CVE Database
/

CVE-2016-4694

Back to search

CVE-2016-4694

Published: Sep 25, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue, a related issue to CVE-2016-5387.

VendorProductVersions

n/a

n/a

affected
n/a

References

93060
vdb-entry
x_refsource_BID
APPLE-SA-2016-09-20
vendor-advisory
x_refsource_APPLE
1036853
vdb-entry
x_refsource_SECTRACK
APPLE-SA-2016-09-20-4
vendor-advisory
x_refsource_APPLE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now