Blog | G5 Cyber Security

Apache HTTP Server 2.2 vulnerabilities

Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32. This is not assigned an httpd severity, as it is a defect in other software which overloaded CGI environment variables, and does not reflect an error in HTTP server software. A mitigation is provided to avoid populating the httpd CGI environment to populate the “HTTP_PROXY” variable from a “Proxy:” header, which has never been registered by IANA.”]

Source: http://httpd.apache.org/security/vulnerabilities_22.html

Exit mobile version