FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2016-1133

This CVE name corresponds to:

Entered Topic
2016-01-15 h2o -- directory traversal vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2016-1133
Phase Assigned(20151226)

Description

CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URI.

References

Source Reference
CONFIRM https://github.com/h2o/h2o/issues/682
CONFIRM https://github.com/h2o/h2o/issues/684
CONFIRM https://h2o.examp1e.net/vulnerabilities.html#CVE-2016-1133
JVN JVN#45928828
JVNDB JVNDB-2016-000003