USN-6671-1: php-nyholm-psr7 vulnerability
Published Feb 29, 2024
·Updated
It was discovered that php-nyholm-psr7 incorrectly parsed HTTP headers. A remote attacker could possibly use this issue to perform an HTTP header injection attack.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/php-nyholm-psr7<1.5.0-1ubuntu0.1~esm1
1.5.0-1ubuntu0.1~esm1
Ubuntu Ubuntu=22.04
Event History
Feb 29, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6671-1?
The severity of USN-6671-1 is categorized as a potential vulnerability that could allow HTTP header injection.
2
How do I fix USN-6671-1?
To mitigate USN-6671-1, update the php-nyholm-psr7 package to version 1.5.0-1ubuntu0.1~esm1 or later.
3
What causes the vulnerability USN-6671-1?
USN-6671-1 is caused by improper parsing of HTTP headers in the php-nyholm-psr7 package.
4
Who is affected by USN-6671-1?
Ubuntu users running php-nyholm-psr7 version less than 1.5.0-1ubuntu0.1~esm1 are affected by USN-6671-1.
5
Can USN-6671-1 be exploited remotely?
Yes, a remote attacker could exploit USN-6671-1 to perform an HTTP header injection attack.