Environment variable injection in TYPO3 in Oracle Linux and TYPO3 - CVE-2016-5385

 

Environment variable injection in TYPO3 in Oracle Linux and TYPO3 - CVE-2016-5385

Published: July 22, 2016 / Updated: January 10, 2017


Vulnerability identifier: #VU194
CSH Severity: High
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2016-5385
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect an application's outbound HTTP traffic.

The vulnerability exists in TYPO3 CMS. A remote attacker can redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request.

Successful exploitation of this vulnerability may result in XSS attack and data injection.

Affected software

Oracle Linux
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Fedora
Red Hat Enterprise Linux EUS Compute Node
Slackware Linux
TYPO3
FlashSystem 840 9840-AE1 & 9843-AE1
FlashSystem 900 9840-AE2 and 9843-AE2
php-guzzlehttp-guzzle
php54-php (Red Hat package)
php55-php (Red Hat package)
rh-php56-php (Red Hat package)
php
php-guzzlehttp-guzzle6
IBM FlashSystem V9000
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700
IBM Storwize V3500

How to mitigate CVE-2016-5385

Install the latest version 8.2.1.

php-guzzlehttp-guzzle - addressed in versions 5.3.1-1.el7, 5.3.1-1.fc23, 5.3.1-1.fc24
php54-php (Red Hat package) - addressed in versions 5.4.40-4.el6, 5.4.40-4.el7
php55-php (Red Hat package) - addressed in versions 5.5.21-5.el6, 5.5.21-5.el7
rh-php56-php (Red Hat package) - addressed in versions 5.6.5-9.el6, 5.6.5-9.el7
php - addressed in versions 5.6.24-1.fc23, 5.6.24-2.fc24
php-guzzlehttp-guzzle6 - addressed in versions 6.2.1-1.fc23, 6.2.1-1.fc24
IBM FlashSystem V9000 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
IBM Storwize V7000 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
IBM Storwize V5000 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
IBM Storwize V3700 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
IBM Storwize V3500 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3

External References

Related Security Bulletins