Bugzilla – Bug 1078298
VUL-1: CVE-2016-10711 Pound: request smuggling via crafted headers
Last modified: 2018-02-08 11:09:04 UTC
Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751. References: https://bugzilla.redhat.com/show_bug.cgi?id=1540187 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-10711 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-10711.html http://www.apsis.ch/pound/pound_list/archive/2016/2016-10/1477235279000
This is an autogenerated message for OBS integration: This bug (1078298) was mentioned in https://build.opensuse.org/request/show/571084 42.3 / pound
https://build.opensuse.org/request/show/571084 https://build.opensuse.org/request/show/571048
This is an autogenerated message for OBS integration: This bug (1078298) was mentioned in https://build.opensuse.org/request/show/571411 Factory / pound
openSUSE-SU-2018:0394-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1078298 CVE References: CVE-2016-10711 Sources used: openSUSE Leap 42.3 (src): pound-2.7-8.1