CVE-2016-1133: CRLF Injection
CRLF injection vulnerability in the onreq function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1133?
CVE-2016-1133 is classified as a high severity vulnerability due to its potential to allow remote attackers to inject arbitrary HTTP headers.
How do I fix CVE-2016-1133?
To fix CVE-2016-1133, you should upgrade to H2O version 1.6.2 or later, or to any version that is beyond 1.7.0-beta3.
What systems are affected by CVE-2016-1133?
CVE-2016-1133 affects H2O versions prior to 1.6.2 and H2O 1.7.0-beta2.
What type of attack can be executed exploiting CVE-2016-1133?
Exploiting CVE-2016-1133 allows attackers to conduct HTTP response splitting attacks via crafted URIs.
Is CVE-2016-1133 an information disclosure vulnerability?
CVE-2016-1133 is not primarily an information disclosure vulnerability but rather allows for header injection and manipulation.