Vulnerability Description
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | 2.2.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/105093Third Party AdvisoryVDB Entry
- https://httpd.apache.org/security/vulnerabilities_22.html#CVE-2016-4975Vendor Advisory
- https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2016-4975Vendor Advisory
- https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cd
- https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e10
- https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772
- https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f74
- https://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7
- https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d65
- https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb
- https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f8
- https://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7a
- https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa
- https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df
FAQ
What is CVE-2016-4975?
CVE-2016-4975 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into t...
How severe is CVE-2016-4975?
CVE-2016-4975 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-4975?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server.