Improper Input Validation Affecting golang-src package, versions <0:1.6.3-1.el7_2.1
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RHEL7-GOLANGSRC-4633109
- published 26 Jul 2021
- disclosed 18 Jul 2016
Introduced: 18 Jul 2016
CVE-2016-5386 Open this link in a new tabHow to fix?
Upgrade RHEL:7
golang-src
to version 0:1.6.3-1.el7_2.1 or higher.
This issue was patched in RHSA-2016:1538
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream golang-src
package and not the golang-src
package as distributed by RHEL
.
See How to fix?
for RHEL:7
relevant fixed versions and status.
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
References
- http://www.kb.cert.org/vuls/id/797896
- https://bugzilla.redhat.com/show_bug.cgi?id=1353798
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- https://access.redhat.com/security/cve/CVE-2016-5386
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7WGHKKCFP4PLVSWQKCM3FJJPEWB5ZNTU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OR52UXGM6RKSCWF3KQMVZGVZVJ3WEESJ/
- https://httpoxy.org/
- http://rhn.redhat.com/errata/RHSA-2016-1538.html
- https://access.redhat.com/errata/RHSA-2016:1538
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WGHKKCFP4PLVSWQKCM3FJJPEWB5ZNTU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OR52UXGM6RKSCWF3KQMVZGVZVJ3WEESJ/