Oval Definition:
oval:com.ubuntu.xenial:def:201496500000000
Revision Date
:
2015-01-27
Version
:
1
Title
:
CVE-2014-9650 on Ubuntu 16.04 LTS (xenial) - low.
Description
:
CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.
Family
:
unix
Class
:
vulnerability
Status
:
Reference(s)
:
CVE-2014-9650
Platform(s)
:
Ubuntu 16.04 LTS
Product(s)
:
Definition Synopsis
Ubuntu 16.04 LTS (xenial) is installed.
AND
rabbitmq-server package in xenial, is related to the CVE in some way and has been fixed (note: '3.4.2-2').
BACK