CVE-2016-5385: Debian Linux

High severity, CVSS 8.1. EPSS: 50.4% chance of exploitation in the next 30 days.

PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Drupal Drupal: from 8.0.0, before 8.1.7 (fixed in 8.1.7)
  • Fedoraproject Fedora: version 23 only; version 24 only
  • HP Storeever MSL6480 Tape Library Firmware: up to and including 5.09
  • HP System Management Homepage: up to and including 7.5.5.0
  • Opensuse Leap: version 42.1 only
  • Oracle Communications User Data Repository: version 10.0.0 only; version 10.0.1 only; version 12.0.0 only
  • Oracle Enterprise Manager Ops Center: version 12.2.2 only; version 12.3.2 only
  • Oracle Linux: version 6 only; version 7 only
  • PHP PHP: from 5.5.0, before 5.5.38 (fixed in 5.5.38); from 5.6.0, before 5.6.24 (fixed in 5.6.24); from 7.0.0, up to and including 7.0.8
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2016-07-19. Last modified 2026-06-17.