Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.140205
Category:F5 Local Security Checks
Title:F5 BIG-IP - Node.js vulnerability CVE-2016-2216
Summary:The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.
Description:Summary:
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.

Vulnerability Impact:
This vulnerability may allow a remote attacker to bypass an HTTP response-splitting protection mechanism.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-2216
BugTraq ID: 83141
http://www.securityfocus.com/bid/83141
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177184.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177673.html
https://security.gentoo.org/glsa/201612-43
http://blog.safebreach.com/2016/02/09/http-response-splitting-in-node-js-root-cause-analysis/
http://info.safebreach.com/hubfs/Node-js-Response-Splitting.pdf
http://packetstormsecurity.com/files/135711/Node.js-HTTP-Response-Splitting.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-9244
BugTraq ID: 96143
http://www.securityfocus.com/bid/96143
https://www.exploit-db.com/exploits/41298/
http://packetstormsecurity.com/files/141017/Ticketbleed-F5-TLS-Information-Disclosure.html
https://blog.filippo.io/finding-ticketbleed/
https://filippo.io/Ticketbleed/
https://github.com/0x00string/oldays/blob/master/CVE-2016-9244.py
http://www.securitytracker.com/id/1037800
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.