CVE-2016-1133

EUVD-2016-2237
CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URI.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
Affected Products (NVD)
VendorProductVersion
denah2o
𝑥
≤ 1.6.1
denah2o
1.7.0:beta2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
h2o
bookworm
2.2.5+dfsg2-7
fixed
bullseye
2.2.5+dfsg2-6
fixed
sid
2.2.5+dfsg2-9
fixed
trixie
2.2.5+dfsg2-9
fixed