HIGH8.1
GHSA-m6ch-gg5f-wxx3
HTTP Proxy header vulnerability
Quick fix
GHSA-m6ch-gg5f-wxx3 — guzzlehttp/guzzle: upgrade to the fixed version with the command below.
composer require guzzlehttp/guzzle:^6.2.1Details
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/guzzlehttp/guzzle
Introduced in:
6Fixed in: 6.2.1Fix
composer require guzzlehttp/guzzle:^6.2.1Packagist/guzzlehttp/guzzle
Introduced in:
4.0.0-rc2Fixed in: 4.2.4Fix
composer require guzzlehttp/guzzle:^4.2.4Packagist/guzzlehttp/guzzle
Introduced in:
5Fixed in: 5.3.1Fix
composer require guzzlehttp/guzzle:^5.3.1Packagist/bugsnag/bugsnag-laravel
Introduced in:
0Fixed in: 2.0.2Fix
composer require bugsnag/bugsnag-laravel:^2.0.2Packagist/padraic/humbug_get_contents
Introduced in:
0Fixed in: 1.1.2Fix
composer require padraic/humbug_get_contents:^1.1.2References
- https://nvd.nist.gov/vuln/detail/CVE-2016-5385[ADVISORY]
- https://github.com/bugsnag/bugsnag-laravel/pull/143[WEB]
- https://github.com/bugsnag/bugsnag-laravel/pull/145[WEB]
- https://github.com/humbug/file_get_contents/pull/23[WEB]
- https://github.com/humbug/file_get_contents/pull/23/commits/848e8c282a863654e76bd958acfb57c81cb739b5[WEB]
- https://github.com/amphp/artax/commit/81254742812a5a9adf4b085f543f3f21daedcd97[WEB]
- https://github.com/amphp/artax/commit/b60cf493c9e577a3678865f620b1eb61ab3d7ca9[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=1353794[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/guzzlehttp/guzzle/CVE-2016-5385.yaml[WEB]
- https://github.com/bugsnag/bugsnag-laravel/releases/tag/v2.0.2[WEB]
- https://github.com/guzzle/guzzle/blob/4.x/CHANGELOG.md#424-2016-07-18[WEB]
- https://github.com/guzzle/guzzle/blob/5.3/CHANGELOG.md#531---2016-07-18[WEB]
- https://github.com/guzzle/guzzle/blob/master/CHANGELOG.md#622---2016-10-08[WEB]
- https://github.com/guzzle/guzzle/releases/tag/6.2.1[WEB]
- https://github.com/humbug/file_get_contents/releases/tag/1.1.2[WEB]
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us[WEB]
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149[WEB]
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05333297[WEB]
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7RMYXAVNYL2MOBJTFATE73TOVOEZYC5R/[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXFEIMZPSVGZQQAYIQ7U7DFVX3IBSDLF/[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZOIUYZDBWNDDHC6XTOLZYRMRXZWTJCP/[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7RMYXAVNYL2MOBJTFATE73TOVOEZYC5R/[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GXFEIMZPSVGZQQAYIQ7U7DFVX3IBSDLF/[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KZOIUYZDBWNDDHC6XTOLZYRMRXZWTJCP/[WEB]
- https://security.gentoo.org/glsa/201611-22[WEB]
- https://www.drupal.org/SA-CORE-2016-003[WEB]
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2016-1609.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2016-1610.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2016-1611.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2016-1612.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2016-1613.html[WEB]
- http://www.debian.org/security/2016/dsa-3631[WEB]
- http://www.kb.cert.org/vuls/id/797896[WEB]
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html[WEB]
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html[WEB]
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html[WEB]
- http://www.securityfocus.com/bid/91821[WEB]
- http://www.securitytracker.com/id/1036335[WEB]