First published: Mon Feb 15 2016(Updated: )
CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=8.0<8.0.4 | |
composer/drupal/drupal | >=8.0<8.0.4 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Drupal Drupal | =6.0 | |
Drupal Drupal | =6.0-beta1 | |
Drupal Drupal | =6.0-beta2 | |
Drupal Drupal | =6.0-beta3 | |
Drupal Drupal | =6.0-beta4 | |
Drupal Drupal | =6.0-dev | |
Drupal Drupal | =6.0-rc1 | |
Drupal Drupal | =6.0-rc2 | |
Drupal Drupal | =6.0-rc3 | |
Drupal Drupal | =6.0-rc4 | |
Drupal Drupal | =6.1 | |
Drupal Drupal | =6.2 | |
Drupal Drupal | =6.3 | |
Drupal Drupal | =6.4 | |
Drupal Drupal | =6.5 | |
Drupal Drupal | =6.6 | |
Drupal Drupal | =6.7 | |
Drupal Drupal | =6.8 | |
Drupal Drupal | =6.9 | |
Drupal Drupal | =6.10 | |
Drupal Drupal | =6.11 | |
Drupal Drupal | =6.12 | |
Drupal Drupal | =6.13 | |
Drupal Drupal | =6.14 | |
Drupal Drupal | =6.15 | |
Drupal Drupal | =6.16 | |
Drupal Drupal | =6.17 | |
Drupal Drupal | =6.18 | |
Drupal Drupal | =6.19 | |
Drupal Drupal | =6.20 | |
Drupal Drupal | =6.21 | |
Drupal Drupal | =6.22 | |
Drupal Drupal | =6.23 | |
Drupal Drupal | =6.24 | |
Drupal Drupal | =6.25 | |
Drupal Drupal | =6.26 | |
Drupal Drupal | =6.27 | |
Drupal Drupal | =6.28 | |
Drupal Drupal | =6.29 | |
Drupal Drupal | =6.30 | |
Drupal Drupal | =6.31 | |
Drupal Drupal | =6.32 | |
Drupal Drupal | =6.33 | |
Drupal Drupal | =6.34 | |
Drupal Drupal | =6.35 | |
Drupal Drupal | =6.36 | |
Drupal Drupal | =6.37 | |
composer/drupal/drupal | >=6.0<6.38 | 6.38 |
composer/drupal/core | >=6.0<6.38 | 6.38 |
=7.0 | ||
=8.0 | ||
=6.0 | ||
=6.0-beta1 | ||
=6.0-beta2 | ||
=6.0-beta3 | ||
=6.0-beta4 | ||
=6.0-dev | ||
=6.0-rc1 | ||
=6.0-rc2 | ||
=6.0-rc3 | ||
=6.0-rc4 | ||
=6.1 | ||
=6.2 | ||
=6.3 | ||
=6.4 | ||
=6.5 | ||
=6.6 | ||
=6.7 | ||
=6.8 | ||
=6.9 | ||
=6.10 | ||
=6.11 | ||
=6.12 | ||
=6.13 | ||
=6.14 | ||
=6.15 | ||
=6.16 | ||
=6.17 | ||
=6.18 | ||
=6.19 | ||
=6.20 | ||
=6.21 | ||
=6.22 | ||
=6.23 | ||
=6.24 | ||
=6.25 | ||
=6.26 | ||
=6.27 | ||
=6.28 | ||
=6.29 | ||
=6.30 | ||
=6.31 | ||
=6.32 | ||
=6.33 | ||
=6.34 | ||
=6.35 | ||
=6.36 | ||
=6.37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.