HTTP: HTTP_PROXY Traffic Redirection

This signature detects attempts to exploit a known vulnerability against HTTP_PROXY environment variable using the Proxy HTTP header. Multiple products which includes PHP, Go, Apache HTTP Server, Apache Tomcat, HHVM, Lighttpd, Nginx and Python are vulnerable. Attackers can control proxy variable using this vulnerability which potentially leads to a man-in-the-middle attack.

Extended Description

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.

Affected Products

Python python

References

CVE: CVE-2016-5387

Short Name
HTTP:HTTP_PROXY-ATTACK
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2016-1000109 CVE-2016-1000110 CVE-2016-5385 CVE-2016-5386 CVE-2016-5387 CVE-2016-5388 HTTP_PROXY Redirection Traffic
Release Date
07/26/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Python

Fedoraproject

Debian

CVSS Score

6.8

5.8

5.1

5.0

Found a potential security threat?