CVE-2016-6286: High severity call-cc http-client vulnerability
The "spiffy-cgi-handlers" egg would convert a nonexistent "Proxy" header to the HTTPPROXY environment variable, which would allow attackers to direct CGI programs which use this environment variable to use an attacker-specified HTTP proxy server (also known as a "httpoxy" attack). This affects all versions of spiffy-cgi-handlers before 0.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6286?
CVE-2016-6286 is considered a medium severity vulnerability due to its potential to allow httpoxy attacks.
How do I fix CVE-2016-6286?
To fix CVE-2016-6286, you should update the affected 'spiffy-cgi-handlers' egg to avoid processing the Proxy header.
Which software is affected by CVE-2016-6286?
CVE-2016-6286 affects the Call-cc Http-client version up to and including 0.4.2.
What type of attack does CVE-2016-6286 facilitate?
CVE-2016-6286 facilitates an httpoxy attack by allowing the manipulation of the HTTP_PROXY environment variable.
Is CVE-2016-6286 still relevant today?
CVE-2016-6286 remains relevant for systems still running vulnerable versions of the affected software.