Oval Definition:oval:org.opensuse.security:def:20161899
Revision Date:2022-06-30Version:1
Title:CVE-2016-1899
Description:

CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via CRLF sequences in the mimetype parameter, as demonstrated by a request to blob/cgit.c.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-1899
Mitre CVE-2016-1899
SUSE CVE-2016-1899
openSUSE-SU-2016:0196-1
openSUSE-SU-2016:0218-1
Platform(s):openSUSE 13.1
openSUSE 13.2
openSUSE Leap 42.1
openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE 13.1 is installed
  • AND cgit-0.12-11.6.1 is installed
  • Definition Synopsis
  • openSUSE 13.2 is installed
  • AND cgit-0.12-13.6.1 is installed
  • Definition Synopsis
  • openSUSE Leap 42.1 is installed
  • AND Package Information
  • cgit-0.12-6.1 is installed
  • AND cgit is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND cgit-1.0-1.3 is installed
  • BACK