Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2018-08-14T13:00:00Z
Updated: 2024-09-16T19:47:03.346Z
Reserved: 2016-05-24T00:00:00
Link: CVE-2016-4975
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-08-14T12:29:00.220
Modified: 2024-11-21T02:53:20.620
Link: CVE-2016-4975
Redhat