CVE-2016-5387
published 2016-07-19CVE-2016-5387: The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in…
PriorityP359high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
55.72%
98.9th percentile
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | 2.2.0 – 2.2.31 | — |
| apache | http_server | 2.4.1 – 2.4.23 | — |
| apple | mac_os_x | <= 10.11.6 | — |
| apple | macos_high_sierra | — | — |
| apple | macos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20 | — | — |
| apple | macos_sierra_10.12.4_security_update_2017-001_el_capitan_and_security_update_201 | — | — |
| apple | os_x_server | <= 5.1 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.4.23-2 (bookworm) | apache2 2.4.23-2 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| hp | system_management_homepage | <= 7.5.5.0 | — |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| oracle | communications_user_data_repository | 10.0.0 – 12.4 | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
| oracle | solaris | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by inspecting HTTP requests for a crafted 'Proxy' header, which Apache HTTP Server would convert into the HTTP_PROXY environment variable and potentially redirect outbound CGI traffic to an attacker-controlled proxy. ↗
- →Monitor CGI script execution environments for the presence of an HTTP_PROXY environment variable sourced from untrusted client-supplied request headers, which is the core exploitation mechanism of the httpoxy attack class. ↗
- →For mod_fcgid deployments, check whether 'FcgidPassHeader Proxy' is configured, as this directive enables the vulnerability even after Apache HTTPD is patched for CVE-2016-5387. ↗
- →Alert on inbound HTTP requests containing a 'Proxy:' header targeting Apache HTTP Server instances running CGI applications, as this is the attacker-controlled input vector for the httpoxy issue. ↗
- ·The vulnerability is only exploitable when CGI scripts honour the HTTP_PROXY environment variable; applications not using CGI or not reading HTTP_PROXY are not affected. ↗
- ·mod_fcgid is only vulnerable if 'FcgidPassHeader Proxy' is explicitly configured; patching Apache HTTPD for CVE-2016-5387 alone is insufficient to protect mod_fcgid when that directive is in use. ↗
- ·CVE-2016-5387 is formally a mitigation identifier assigned by the Apache vendor, not a traditional vulnerability CVE; the underlying protocol issue stems from RFC 3875 section 4.1.18 compliance. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_redhat8.8HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r72m-c53q-265m: The Apache HTTP Server in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 8.1
CVE-2016-4694 [HIGH] CWE-284 GHSA-r72m-c53q-265m: The Apache HTTP Server in Apple OS X before 10
The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue, a related issue to CVE-2016-5387.
GHSA
GHSA-9hqr-6p2v-pfp2: The Apache HTTP Server through 2
ghsa_unreviewed·2022-05-13·CVSS 8.1
CVE-2016-5387 [HIGH] CWE-284 GHSA-9hqr-6p2v-pfp2: The Apache HTTP Server through 2
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
OSV
CVE-2016-5387: The Apache HTTP Server through 2
osv·2016-07-19·CVSS 8.1
CVE-2016-5387 [HIGH] CVE-2016-5387: The Apache HTTP Server through 2
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
Apple
CVE-2016-5387: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
vendor_apple·2017-10-31·CVSS 8.1
CVE-2016-5387 [HIGH] CVE-2016-5387: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
Product: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
CVE: CVE-2016-5387
Component: CVE-2016-5387
Apple
CVE-2016-5387: macOS High Sierra 10.13
vendor_apple·2017-09-25·CVSS 8.1
CVE-2016-5387 [HIGH] CVE-2016-5387: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2016-5387
Component: CVE-2016-5387
Apple
CVE-2016-5387: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
vendor_apple·2017-03-27·CVSS 8.1
CVE-2016-5387 [HIGH] CVE-2016-5387: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
Apple Security Update: About the security content of macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
Product: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
CVE: CVE-2016-5387
Component: CVE-2016-5387
Red Hat
mod_fcgid: mod_fcgid sets environmental variable based on user supplied Proxy request header
vendor_redhat·2016-07-18·CVSS 8.8
CVE-2016-1000104 [HIGH] CWE-20 mod_fcgid: mod_fcgid sets environmental variable based on user supplied Proxy request header
mod_fcgid: mod_fcgid sets environmental variable based on user supplied Proxy request header
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
Statement: This issue is addressed through the Apache HTTPD update for CVE-2016-5387 which prevent the Proxy header from automatically being converted into the HTTP_PROXY environmental variable. Unless the "FcgidPassHeader Proxy" is used mod_fcgid is not vulnerable to this attack when used with updated HTTPD. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: mod_fcgid (Red Hat Enterprise Linux 7) - Will not fix
Ubuntu
Apache HTTP Server vulnerability
vendor_ubuntu·2016-07-18
CVE-2016-5387 Apache HTTP Server vulnerability
Title: Apache HTTP Server vulnerability
Summary: A security issue was fixed in the Apache HTTP Server.
It was discovered that the Apache HTTP Server would set the HTTP_PROXY
environment variable based on the contents of the Proxy header from HTTP
requests. A remote attacker could possibly use this issue in combination
with CGI scripts that honour the HTTP_PROXY variable to redirect outgoing
HTTP requests.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
HTTPD: sets environmental variable based on user supplied Proxy request header
vendor_redhat·2016-07-18·CVSS 8.1
CVE-2016-5387 [HIGH] CWE-20 HTTPD: sets environmental variable based on user supplied Proxy request header
HTTPD: sets environmental variable based on user supplied Proxy request header
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
It was discovered that httpd used the value of the Proxy header from HTTP requests to initialize the HTTP_PROXY environment variable for CGI scripts, which in turn was incorrectly used by
Debian
CVE-2016-5387: apache2 - The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and theref...
vendor_debian·2016·CVSS 8.1
CVE-2016-5387 [HIGH] CVE-2016-5387: apache2 - The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and theref...
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
Scope: local
bookworm: resolved (fixed in 2.4.23-2)
bullseye: resolved (fixed in 2.4.23-2)
forky: resolved (fixed in 2.4.23-2)
sid: resolved (fixed in 2.4.23-2)
trixie: resolved (fixed in 2.4.23-2)
No detection rules found.
No public exploits indexed.
Tenable
[R5] SecurityCenter 5.4.3 Fixes Multiple Vulnerabilities
blogs_tenable·2017-02-14
[R5] SecurityCenter 5.4.3 Fixes Multiple Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2016-5387 Apache HTTPD: sets environmental variable based on user supplied Proxy request header [jbews-2.1.0]
bugzilla·2016-07-20·CVSS 8.1
CVE-2016-5387 [HIGH] CVE-2016-5387 Apache HTTPD: sets environmental variable based on user supplied Proxy request header [jbews-2.1.0]
CVE-2016-5387 Apache HTTPD: sets environmental variable based on user supplied Proxy request header [jbews-2.1.0]
jbews-2.1.0 tracking bug for httpd: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the blocked bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
EAP 5.2:
HTTPD wasn't shipped with EAP 5.2. Customers had to have a subscription to EWS for httpd support. This was changed in EAP 6.4.9 when httpd became bundled. There is a httpd.dll that appears in the natives which is being investigated. Customers still using EAP 5.2 are directed to use the EWS 2.1.1 release currently GA early August.
jclere:
After some research the httpd comes from EWS per:
https://access.redhat.com
Bugzilla
CVE-2016-5387 Apache HTTPD: sets environmental variable based on user supplied Proxy request header [fedora-all]
bugzilla·2016-07-18·CVSS 8.1
CVE-2016-5387 [HIGH] CVE-2016-5387 Apache HTTPD: sets environmental variable based on user supplied Proxy request header [fedora-all]
CVE-2016-5387 Apache HTTPD: sets environmental variable based on user supplied Proxy request header [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2016-1000104 mod_fcgid: mod_fcgid sets environmental variable based on user supplied Proxy request header
bugzilla·2016-07-07·CVSS 8.8
CVE-2016-1000104 [HIGH] CVE-2016-1000104 mod_fcgid: mod_fcgid sets environmental variable based on user supplied Proxy request header
CVE-2016-1000104 mod_fcgid: mod_fcgid sets environmental variable based on user supplied Proxy request header
Dominic Scheirlinck of VendHQ reports:
Many software projects and vendors have implemented support for the “Proxy” request header in their respective CGI implementations and languages by creating the “HTTP_PROXY” environmental variable based on the header value. When this variable is used (in many cases automatically by various HTTP client libraries) any outgoing requests generated in turn from the attackers original request can be redirected to an attacker controlled proxy. This allows attackers to view potentially sensitive information, reply with malformed data, or to hold connections open causing a potential denial of service.
The mod_fcgi module provides support for CGI. If
Bugzilla
CVE-2016-5387 HTTPD: sets environmental variable based on user supplied Proxy request header
bugzilla·2016-07-07·CVSS 8.1
CVE-2016-5387 [HIGH] CVE-2016-5387 HTTPD: sets environmental variable based on user supplied Proxy request header
CVE-2016-5387 HTTPD: sets environmental variable based on user supplied Proxy request header
Dominic Scheirlinck of VendHQ reports:
Many software projects and vendors have implemented support for the “Proxy” request header in their respective CGI implementations and languages by creating the “HTTP_PROXY” environmental variable based on the header value. When this variable is used (in many cases automatically by various HTTP client libraries) any outgoing requests generated in turn from the attackers original request can be redirected to an attacker controlled proxy. This allows attackers to view potentially sensitive information, reply with malformed data, or to hold connections open causing a potential denial of service.
The Apache HTTPD server sets various environmental variables base
http://lists.opensuse.org/opensuse-updates/2016-07/msg00059.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1624.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1625.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1648.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1649.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1650.htmlhttp://www.debian.org/security/2016/dsa-3623http://www.kb.cert.org/vuls/id/797896http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.securityfocus.com/bid/91816http://www.securitytracker.com/id/1036330http://www.ubuntu.com/usn/USN-3038-1https://access.redhat.com/errata/RHSA-2016:1420https://access.redhat.com/errata/RHSA-2016:1421https://access.redhat.com/errata/RHSA-2016:1422https://access.redhat.com/errata/RHSA-2016:1635https://access.redhat.com/errata/RHSA-2016:1636https://access.redhat.com/errata/RHSA-2016:1851https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_ushttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://httpoxy.org/https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WCTE7443AYZ4EGELWLVNANA2WJCJIYI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NEKZAB7MTWVSMORHTEMCQNFFMIHCYF76/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QPQAPWQA774JPDRV4UIB2SZAX6D3UZCV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TGNHXJJSWDXAOEYH5TMXDPQVJMQQJOAZ/https://security.gentoo.org/glsa/201701-36https://support.apple.com/HT208221https://www.apache.org/security/asf-httpoxy-response.txthttps://www.tenable.com/security/tns-2017-04http://lists.opensuse.org/opensuse-updates/2016-07/msg00059.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1624.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1625.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1648.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1649.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1650.htmlhttp://www.debian.org/security/2016/dsa-3623http://www.kb.cert.org/vuls/id/797896http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.securityfocus.com/bid/91816http://www.securitytracker.com/id/1036330http://www.ubuntu.com/usn/USN-3038-1https://access.redhat.com/errata/RHSA-2016:1420https://access.redhat.com/errata/RHSA-2016:1421https://access.redhat.com/errata/RHSA-2016:1422https://access.redhat.com/errata/RHSA-2016:1635https://access.redhat.com/errata/RHSA-2016:1636https://access.redhat.com/errata/RHSA-2016:1851https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_ushttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://httpoxy.org/https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E
+ 8 more references
2016-07-19
Published