Show plain JSON{"acknowledgement": "Red Hat would like to thank Scott Geary (VendHQ) for reporting this issue.", "affected_release": [{"advisory": "RHSA-2016:1626", "cpe": "cpe:/o:redhat:enterprise_linux:6", "package": "python-0:2.6.6-66.el6_8", "product_name": "Red Hat Enterprise Linux 6", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1626", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "python-0:2.7.5-38.el7_2", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1628", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-0:2.7.8-18.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1629", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python33-python-0:3.3.2-18.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1630", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "rh-python34-python-0:3.4.2-14.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1628", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-0:2.7.8-18.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1629", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python33-python-0:3.3.2-18.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1630", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "rh-python34-python-0:3.4.2-14.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1628", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-0:2.7.8-18.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1629", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python33-python-0:3.3.2-18.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1630", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "rh-python34-python-0:3.4.2-14.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1627", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "rh-python35-python-0:3.5.1-9.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1628", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-0:2.7.8-16.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1629", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python33-python-0:3.3.2-16.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1630", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "rh-python34-python-0:3.4.2-13.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1627", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "rh-python35-python-0:3.5.1-9.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1628", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-0:2.7.8-16.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1629", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python33-python-0:3.3.2-16.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1630", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "rh-python34-python-0:3.4.2-13.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1627", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "rh-python35-python-0:3.5.1-9.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1628", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-0:2.7.8-16.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1629", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python33-python-0:3.3.2-16.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS", "release_date": "2016-08-18T00:00:00Z"}, {"advisory": "RHSA-2016:1630", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "rh-python34-python-0:3.4.2-13.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS", "release_date": "2016-08-18T00:00:00Z"}], "bugzilla": {"description": "CGIHandler: sets environmental variable based on user supplied Proxy request header", "id": "1357334", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1357334"}, "csaw": false, "cvss": {"cvss_base_score": "5.0", "cvss_scoring_vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N", "status": "verified"}, "cvss3": {"cvss3_base_score": "5.0", "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N", "status": "verified"}, "cwe": "CWE-20", "details": ["The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.", "It was discovered that the Python CGIHandler class did not properly protect against the HTTP_PROXY variable name clash in a CGI context. A remote attacker could possibly use this flaw to redirect HTTP requests performed by a Python CGI script to an attacker-controlled proxy via a malicious HTTP request."], "name": "CVE-2016-1000110", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:4", "fix_state": "Will not fix", "package_name": "python", "product_name": "Red Hat Enterprise Linux 4"}, {"cpe": "cpe:/o:redhat:enterprise_linux:5", "fix_state": "Affected", "package_name": "python", "product_name": "Red Hat Enterprise Linux 5"}], "public_date": "2016-07-18T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2016-1000110\nhttps://nvd.nist.gov/vuln/detail/CVE-2016-1000110"], "threat_severity": "Moderate"}