VDB
SUSE-SU-2016%3A2941-1
SUSE-SU-2016%3A2941-1
PUBLISHED
CVSS 8.100000381469727 HIGH
Security update for php7
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apache2 | ||
| php7 |
Exploit Intelligence
- https://www.suse.com/support/security/rating/ (circl)
- https://ftp.suse.com/pub/projects/security/csaf/suse-su-2016_2941-1.json (circl)
- https://www.suse.com/support/update/announcement/2016/suse-su-20162941-1/ (circl)
- https://lists.suse.com/pipermail/sle-security-updates/2016-November/002428.html (circl)
- https://bugzilla.suse.com/1008029 (circl)
- https://bugzilla.suse.com/988486 (circl)
- https://www.suse.com/security/cve/CVE-2016-5385/ (circl)
- https://www.suse.com/security/cve/CVE-2016-9137/ (circl)
- Attempts to detect web applications vulnerable to "httpoxy" (CVE-2016-5385, CVE-2016-5386, CVE-2016-5387, CVE-2016-5388, CVE-2016-1000109, CVE-2016-1000110). The script attempts to detect this vulnerability by measuring the response time when assigning a non-existing proxy to the headers. In theory, vulnerable applications will try to connect to the bad proxy increasing the response time. To reduce false positives we run the test several times and we expect the response time from the request ... (nmap-nse)
- Attempts to detect web applications vulnerable to "httpoxy" (CVE-2016-5385, CVE-2016-5386, CVE-2016-5387, CVE-2016-5388, CVE-2016-1000109, CVE-2016-1000110). The script attempts to detect this vulnerability by measuring the response time when assigning a non-existing proxy to the headers. In theory, vulnerable applications will try to connect to the bad proxy increasing the response time. To reduce false positives we run the test several times and we expect the response time from the request ... (nmap-nse)
Timeline
- Jul 22, 2016 PoC Published
- Nov 29, 2016 CVE Published
- Feb 4, 2026 CVE Updated
References
- https://www.suse.com/support/security/rating/ url
- https://ftp.suse.com/pub/projects/security/csaf/suse-su-2016_2941-1.json advisory
- https://www.suse.com/support/update/announcement/2016/suse-su-20162941-1/ advisory
- https://lists.suse.com/pipermail/sle-security-updates/2016-November/002428.html advisory
- https://bugzilla.suse.com/1008029 advisory
- https://bugzilla.suse.com/988486 advisory
- https://www.suse.com/security/cve/CVE-2016-5385/ advisory
- https://www.suse.com/security/cve/CVE-2016-9137/ advisory