Oval Definition:oval:org.opensuse.security:def:20165386
Revision Date:2023-06-22Version:1
Title:CVE-2016-5386
Description:

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-5386
Mitre CVE-2016-5386
SUSE CVE-2016-5386
openSUSE-SU-2016:2054-1
openSUSE-SU-2016:2054-1
openSUSE-SU-2016:2055-1
openSUSE-SU-2016:2055-1
openSUSE-SU-2016:2536-1
openSUSE-SU-2016:2536-1
Platform(s):openSUSE 13.2
openSUSE Leap 42.1
openSUSE Tumbleweed
SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Module for Development Tools 15 SP5
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP5
SUSE Package Hub for SUSE Linux Enterprise 12
Product(s):
Definition Synopsis
  • openSUSE 13.2 is installed
  • AND Package Information
  • go-1.4.3-18.1 is installed
  • OR go-doc-1.4.3-18.1 is installed
  • Definition Synopsis
  • openSUSE Leap 42.1 is installed
  • AND Package Information
  • go-1.6.2-21.1 is installed
  • AND go is signed with openSUSE key
  • OR
  • go-doc-1.6.2-21.1 is installed
  • AND go-doc is signed with openSUSE key
  • Definition Synopsis
  • SUSE Package Hub for SUSE Linux Enterprise 12 is installed
  • AND Package Information
  • go-1.6.1-6 is installed
  • OR go-doc-1.6.1-6 is installed
  • OR go1.4-1.4.3-6 is installed
  • OR go1.4-doc-1.4.3-6 is installed
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • go-1.17-1.1 is installed
  • OR go-doc-1.17-1.1 is installed
  • OR go-race-1.17-1.1 is installed
  • OR go1.10-1.10.8-8.2 is installed
  • OR go1.10-doc-1.10.8-8.2 is installed
  • OR go1.10-race-1.10.8-8.2 is installed
  • OR go1.11-1.11.13-10.5 is installed
  • OR go1.11-doc-1.11.13-10.5 is installed
  • OR go1.11-race-1.11.13-10.5 is installed
  • OR go1.12-1.12.17-4.8 is installed
  • OR go1.12-doc-1.12.17-4.8 is installed
  • OR go1.12-race-1.12.17-4.8 is installed
  • OR go1.4-1.4.3-12.2 is installed
  • OR go1.4-doc-1.4.3-12.2 is installed
  • OR go1.4-race-1.4.3-12.2 is installed
  • OR go1.9-1.9.7-11.2 is installed
  • OR go1.9-doc-1.9.7-11.2 is installed
  • OR go1.9-race-1.9.7-11.2 is installed
  • Definition Synopsis
  • SUSE Package Hub for SUSE Linux Enterprise 12 is installed
  • AND Package Information
  • go-1.6.1-6.1 is installed
  • OR go-doc-1.6.1-6.1 is installed
  • OR go1.4-1.4.3-6.1 is installed
  • OR go1.4-doc-1.4.3-6.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Development Tools 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND go-1.19-150000.3.26.1 is installed
  • BACK