Bug 989997 (CVE-2016-1000111) - VUL-0: CVE-2016-1000111: python-Twisted: sets environmental variable based on user supplied Proxy request header
Summary: VUL-0: CVE-2016-1000111: python-Twisted: sets environmental variable based o...
Status: RESOLVED FIXED
Alias: CVE-2016-1000111
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Thomas Bechtold
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/171045/
Whiteboard: CVSSv2:RedHat:CVE-2016-1000111:5.0:(A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-07-21 13:17 UTC by Johannes Segitz
Modified: 2018-12-16 07:54 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2016-07-21 13:17:27 UTC
rh#1357345

Dominic Scheirlinck of VendHQ reports:

Many software projects and vendors have implemented support for the “Proxy” request header in their respective CGI implementations and languages by creating the “HTTP_PROXY” environmental variable based on the header value. When this variable is used (in many cases automatically by various HTTP client libraries) any outgoing requests generated in turn from the attackers original request can be redirected to an attacker controlled proxy. This allows attackers to view potentially sensitive information, reply with malformed data, or to hold connections open causing a potential denial of service.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1357345
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1000111
http://seclists.org/oss-sec/2016/q3/95
http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-1000111.html
Comment 1 Swamp Workflow Management 2016-07-21 22:01:26 UTC
bugbot adjusting priority
Comment 3 Swamp Workflow Management 2016-12-14 17:11:08 UTC
openSUSE-SU-2016:3157-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 989997
CVE References: CVE-2016-1000111
Sources used:
openSUSE Leap 42.1 (src):    python-Twisted-15.4.0-3.1
Comment 4 Swamp Workflow Management 2017-01-12 14:08:59 UTC
SUSE-SU-2017:0114-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 989997
CVE References: CVE-2016-1000111
Sources used:
SUSE Linux Enterprise Module for Web Scripting 12 (src):    python-Twisted-15.2.1-8.1
SUSE Enterprise Storage 4 (src):    python-Twisted-15.2.1-8.1
SUSE Enterprise Storage 3 (src):    python-Twisted-15.2.1-8.1
Comment 8 Johannes Segitz 2018-10-09 13:38:14 UTC
fixed in all current products