CVE-2016-10711: Critical severity debian linux vulnerability
Published Jan 29, 2018
·Updated
Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.
Affected Software
2 affected components
Debian Debian Linux=7.0
APSIS Pound<=2.7
Event History
Jan 29, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10711?
CVE-2016-10711 has a medium severity level due to its potential for request smuggling, which can lead to unauthorized access or data leakage.
2
How do I fix CVE-2016-10711?
To fix CVE-2016-10711, upgrade to APSIS Pound version 2.8a or later, or ensure you are using a Debian version that is not vulnerable.
3
Which versions of APSIS Pound are affected by CVE-2016-10711?
CVE-2016-10711 affects all versions of APSIS Pound up to 2.7.
4
Is Debian Linux 7.0 affected by CVE-2016-10711?
Yes, Debian Linux 7.0 is affected by CVE-2016-10711 and users are advised to upgrade to a fixed version.
5
What type of attack does CVE-2016-10711 enable?
CVE-2016-10711 enables request smuggling attacks via crafted headers, allowing attackers to manipulate requests between servers.