CVE-2016-4975

Modified
Published: 14 Aug 2018, 13:00
Last modified:16 Sept 2024, 19:47

Vulnerability Summary

Overall Risk (default)
medium
39/100
CVSS Score
6.1 MEDIUM
v3.0 (nvd)
EPSS Score
73.27% CRITICAL
73% probability +0.26%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Aug 2018, 13:00
Published
Vulnerability first disclosed
16 Sept 2024, 19:47
Last Modified
Vulnerability information updated

Description

Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31).

CVSS Metrics

  • v3.0MEDIUMScore: 6.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 73.27% Percentile: 99%

Techniques & Countermeasures

  • CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')

    The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Affected Systems

  • apache software foundationapache http server

    Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23) | Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31)

  • UnknownHTTP Server

    2.2.0 | 2.2.2 | 2.2.3 | 2.2.4 | 2.2.6 | 2.2.8 | 2.2.9 | 2.2.10 | 2.2.11 | 2.2.12 | 2.2.13 | 2.2.14 | 2.2.15 | 2.2.16 | 2.2.17 | 2.2.18 | 2.2.19 | 2.2.20 | 2.2.21 | 2.2.22 | 2.2.23 | 2.2.24 | 2.2.25 | 2.2.26 | 2.2.27 | 2.2.29 | 2.2.31 | 2.4.1 | 2.4.2 | 2.4.3 | 2.4.4 | 2.4.6 | 2.4.7 | 2.4.9 | 2.4.10 | 2.4.12 | 2.4.16 | 2.4.17 | 2.4.18 | 2.4.20 | 2.4.23

References (24)