CVE-2016-4975
Last modified
CVE-2016-4975 is a vulnerability of currently unknown severity. Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. EPSS estimates a 19.80% chance of exploitation in the next 30 days.
Description
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | 2.2.0 |
| Apache | Http Server | 2.2.2 |
| Apache | Http Server | 2.2.3 |
| Apache | Http Server | 2.2.4 |
| Apache | Http Server | 2.2.6 |
| Apache | Http Server | 2.2.8 |
| Apache | Http Server | 2.2.9 |
| Apache | Http Server | 2.2.10 |
| Apache | Http Server | 2.2.11 |
| Apache | Http Server | 2.2.12 |
| Apache | Http Server | 2.2.13 |
| Apache | Http Server | 2.2.14 |
| Apache | Http Server | 2.2.15 |
| Apache | Http Server | 2.2.16 |
| Apache | Http Server | 2.2.17 |
| Apache | Http Server | 2.2.18 |
| Apache | Http Server | 2.2.19 |
| Apache | Http Server | 2.2.20 |
| Apache | Http Server | 2.2.21 |
| Apache | Http Server | 2.2.22 |
| Apache | Http Server | 2.2.23 |
| Apache | Http Server | 2.2.24 |
| Apache | Http Server | 2.2.25 |
| Apache | Http Server | 2.2.26 |
| Apache | Http Server | 2.2.27 |
| Apache | Http Server | 2.2.29 |
| Apache | Http Server | 2.2.31 |
| Apache | Http Server | 2.4.1 |
| Apache | Http Server | 2.4.2 |
| Apache | Http Server | 2.4.3 |
| Apache | Http Server | 2.4.4 |
| Apache | Http Server | 2.4.6 |
| Apache | Http Server | 2.4.7 |
| Apache | Http Server | 2.4.9 |
| Apache | Http Server | 2.4.10 |
| Apache | Http Server | 2.4.12 |
| Apache | Http Server | 2.4.16 |
| Apache | Http Server | 2.4.17 |
| Apache | Http Server | 2.4.18 |
| Apache | Http Server | 2.4.20 |
| Apache | Http Server | 2.4.23 |
References
- http://www.securityfocus.com/bid/105093Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20180926-0006/Third Party Advisory
- http://www.securityfocus.com/bid/105093Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20180926-0006/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-4975?
How severe is CVE-2016-4975?
How do I fix CVE-2016-4975?
Are you affected by CVE-2016-4975?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
