MGASA-2016-0398

Source
https://advisories.mageia.org/MGASA-2016-0398.html
Import Source
https://advisories.mageia.org/MGASA-2016-0398.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0398
Upstream
  • CVE-2016-1000212
Published
2016-11-25T17:04:30Z
Modified
2026-04-16T06:25:24Z
Summary
Updated lighttpd packages fix security vulnerability
Details

Dominic Scheirlinck and Scott Geary of Vend reported an insecure behaviour in the lighttpd web server. Lighttpd assigned Proxy header values from client requests to internal HTTP_PROXY environment variables. This could be used to carry out Man in the Middle Attacks (MIDM) or create connections to arbitrary hosts (CVE-2016-1000212).

References
Credits

Affected packages

Mageia:5 / lighttpd

Package

Name
lighttpd
Purl
pkg:rpm/mageia/lighttpd?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.37-1.1.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2016-0398.json"