CVE-2016-8024: High severity mcafee virusscan enterprise vulnerability
Published Mar 14, 2017
·Updated
Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to obtain sensitive information via the server HTTP response spoofing.
Affected Software
1 affected component
McAfee Virusscan Enterprise Linux<=2.0.3
Event History
Mar 14, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-8024?
CVE-2016-8024 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-8024?
To mitigate CVE-2016-8024, upgrade Intel Security VirusScan Enterprise Linux to version 2.0.4 or later.
3
What type of vulnerability is CVE-2016-8024?
CVE-2016-8024 is an HTTP response header injection vulnerability.
4
Who is affected by CVE-2016-8024?
CVE-2016-8024 affects users of Intel Security VirusScan Enterprise Linux version 2.0.3 and earlier.
5
What could an attacker do with CVE-2016-8024?
An attacker could exploit CVE-2016-8024 to spoof server responses and potentially gain access to sensitive information.