A remote attacker could have set the HTTP_PROXY environment variable of CGI scripts (CVE-2016-1000104).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0203.json"