First published: Sat Jan 16 2016(Updated: )
CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URI.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Dena H20 | <=1.6.1 | |
Dena H20 | =1.7.0-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1133 is classified as a high severity vulnerability due to its potential to allow remote attackers to inject arbitrary HTTP headers.
To fix CVE-2016-1133, you should upgrade to H2O version 1.6.2 or later, or to any version that is beyond 1.7.0-beta3.
CVE-2016-1133 affects H2O versions prior to 1.6.2 and H2O 1.7.0-beta2.
Exploiting CVE-2016-1133 allows attackers to conduct HTTP response splitting attacks via crafted URIs.
CVE-2016-1133 is not primarily an information disclosure vulnerability but rather allows for header injection and manipulation.