Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.
References
Link | Resource |
---|---|
http://www.apsis.ch/pound/pound_list/archive/2016/2016-10/1477235279000 | Release Notes Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2018/02/msg00015.html | Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2020/04/msg00028.html | |
https://lists.debian.org/debian-lts-announce/2020/05/msg00003.html |
Information
Published : 2018-01-29 12:29
Updated : 2020-04-30 11:15
NVD link : CVE-2016-10711
Mitre link : CVE-2016-10711
JSON object : View
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
Products Affected
debian
- debian_linux
apsis
- pound