Trend Micro Security

Apache HTTP Server HTTP Proxy Header Injection Vulnerability (CVE-2016-5387)

  危険度: : 緊急

  概要

A traffic redirection vulnerability has been reported in PHP, Go, Apache HTTP Server, Apache Tomcat, HHVM, Lighttpd, Nginx and Python. This vulnerability allows attackers to set the HTTP_PROXY environment variable using the Proxy HTTP header. This vulnerability may be exploited by a remote attacker to redirect traffic through an attacker controlled proxy, potentially leading to a man-in-the-middle attack.

  トレンドマイクロの対策

Apply associated Trend Micro DPI Rules.

  対応方法

  Trend Micro Deep Security DPI Rule Number: 1007872