{"schema_version":"1.7.3","id":"GHSA-m6ch-gg5f-wxx3","published":"2022-04-07T13:59:22Z","modified":"2023-11-08T03:58:31.024570Z","aliases":["CVE-2016-5385"],"summary":"HTTP Proxy header vulnerability","details":"PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an \"httpoxy\" issue.","affected":[{"package":{"name":"guzzlehttp/guzzle","ecosystem":"Packagist","purl":"pkg:composer/guzzlehttp/guzzle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6"},{"fixed":"6.2.1"}]}],"versions":["6.0.0","6.0.1","6.0.2","6.1.0","6.1.1","6.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-m6ch-gg5f-wxx3/GHSA-m6ch-gg5f-wxx3.json"}},{"package":{"name":"guzzlehttp/guzzle","ecosystem":"Packagist","purl":"pkg:composer/guzzlehttp/guzzle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0-rc2"},{"fixed":"4.2.4"}]}],"versions":["4.0.0","4.0.0-rc.2","4.0.1","4.0.2","4.1.0","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.1.7","4.1.8","4.2.0","4.2.1","4.2.2","4.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-m6ch-gg5f-wxx3/GHSA-m6ch-gg5f-wxx3.json"}},{"package":{"name":"guzzlehttp/guzzle","ecosystem":"Packagist","purl":"pkg:composer/guzzlehttp/guzzle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5"},{"fixed":"5.3.1"}]}],"versions":["5.0.0","5.0.1","5.0.2","5.0.3","5.1.0","5.2.0","5.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-m6ch-gg5f-wxx3/GHSA-m6ch-gg5f-wxx3.json"}},{"package":{"name":"drupal/core","ecosystem":"Packagist","purl":"pkg:composer/drupal/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0"},{"fixed":"8.1.7"}]}],"versions":["8.0.0","8.0.0-beta10","8.0.0-beta11","8.0.0-beta12","8.0.0-beta13","8.0.0-beta14","8.0.0-beta15","8.0.0-beta16","8.0.0-beta6","8.0.0-beta7","8.0.0-beta8","8.0.0-beta9","8.0.0-rc1","8.0.0-rc2","8.0.0-rc3","8.0.0-rc4","8.0.1","8.0.2","8.0.3","8.0.4","8.0.5","8.0.6","8.1.0","8.1.0-beta1","8.1.0-beta2","8.1.0-rc1","8.1.1","8.1.2","8.1.3","8.1.4","8.1.5","8.1.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-m6ch-gg5f-wxx3/GHSA-m6ch-gg5f-wxx3.json"}},{"package":{"name":"bugsnag/bugsnag-laravel","ecosystem":"Packagist","purl":"pkg:composer/bugsnag/bugsnag-laravel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.2"}]}],"versions":["v1.0.0","v1.0.1","v1.0.10","v1.0.2","v1.0.3","v1.0.4","v1.0.5","v1.0.6","v1.0.7","v1.0.8","v1.0.9","v1.1.0","v1.1.1","v1.2.0","v1.2.1","v1.3.0","v1.4.0","v1.4.1","v1.4.2","v1.5.0","v1.5.1","v1.6.0","v1.6.1","v1.6.2","v1.6.3","v1.6.4","v1.7.0","v2.0.0","v2.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-m6ch-gg5f-wxx3/GHSA-m6ch-gg5f-wxx3.json"}},{"package":{"name":"amphp/artax","ecosystem":"Packagist","purl":"pkg:composer/amphp/artax"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.4"}]}],"versions":["v0.1.0","v0.3.7","v0.4.0","v0.5.0","v0.5.1","v0.6.0","v0.6.1","v0.6.2","v0.7.0","v0.7.1","v1.0.0","v1.0.0-alpha","v1.0.0-beta","v1.0.0-beta2","v1.0.0-rc1","v1.0.0-rc2","v1.0.0-rc3","v1.0.0-rc4","v1.0.0-rc5","v1.0.0-rc6","v1.0.1","v1.0.2","v1.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-m6ch-gg5f-wxx3/GHSA-m6ch-gg5f-wxx3.json"}},{"package":{"name":"amphp/artax","ecosystem":"Packagist","purl":"pkg:composer/amphp/artax"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.4"}]}],"versions":["2.0.2","v2.0.0","v2.0.1","v2.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-m6ch-gg5f-wxx3/GHSA-m6ch-gg5f-wxx3.json"}},{"package":{"name":"padraic/humbug_get_contents","ecosystem":"Packagist","purl":"pkg:composer/padraic/humbug_get_contents"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.2"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.1.0","1.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-m6ch-gg5f-wxx3/GHSA-m6ch-gg5f-wxx3.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-5385"},{"type":"WEB","url":"https://github.com/bugsnag/bugsnag-laravel/pull/143"},{"type":"WEB","url":"https://github.com/bugsnag/bugsnag-laravel/pull/145"},{"type":"WEB","url":"https://github.com/humbug/file_get_contents/pull/23"},{"type":"WEB","url":"https://github.com/humbug/file_get_contents/pull/23/commits/848e8c282a863654e76bd958acfb57c81cb739b5"},{"type":"WEB","url":"https://github.com/amphp/artax/commit/81254742812a5a9adf4b085f543f3f21daedcd97"},{"type":"WEB","url":"https://github.com/amphp/artax/commit/b60cf493c9e577a3678865f620b1eb61ab3d7ca9"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1353794"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/guzzlehttp/guzzle/CVE-2016-5385.yaml"},{"type":"WEB","url":"https://github.com/bugsnag/bugsnag-laravel/releases/tag/v2.0.2"},{"type":"WEB","url":"https://github.com/guzzle/guzzle/blob/4.x/CHANGELOG.md#424-2016-07-18"},{"type":"WEB","url":"https://github.com/guzzle/guzzle/blob/5.3/CHANGELOG.md#531---2016-07-18"},{"type":"WEB","url":"https://github.com/guzzle/guzzle/blob/master/CHANGELOG.md#622---2016-10-08"},{"type":"WEB","url":"https://github.com/guzzle/guzzle/releases/tag/6.2.1"},{"type":"WEB","url":"https://github.com/humbug/file_get_contents/releases/tag/1.1.2"},{"type":"WEB","url":"https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us"},{"type":"WEB","url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149"},{"type":"WEB","url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05333297"},{"type":"WEB","url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7RMYXAVNYL2MOBJTFATE73TOVOEZYC5R/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXFEIMZPSVGZQQAYIQ7U7DFVX3IBSDLF/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZOIUYZDBWNDDHC6XTOLZYRMRXZWTJCP/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7RMYXAVNYL2MOBJTFATE73TOVOEZYC5R/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GXFEIMZPSVGZQQAYIQ7U7DFVX3IBSDLF/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KZOIUYZDBWNDDHC6XTOLZYRMRXZWTJCP/"},{"type":"WEB","url":"https://security.gentoo.org/glsa/201611-22"},{"type":"WEB","url":"https://www.drupal.org/SA-CORE-2016-003"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2016-1609.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2016-1610.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2016-1611.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2016-1612.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2016-1613.html"},{"type":"WEB","url":"http://www.debian.org/security/2016/dsa-3631"},{"type":"WEB","url":"http://www.kb.cert.org/vuls/id/797896"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/91821"},{"type":"WEB","url":"http://www.securitytracker.com/id/1036335"}],"database_specific":{"cwe_ids":["CWE-601"],"github_reviewed":true,"github_reviewed_at":"2022-04-07T13:59:22Z","nvd_published_at":"2016-07-19T02:00:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}