Critical severity9.1NVD Advisory· Published Sep 25, 2016· Updated May 6, 2026
CVE-2016-4694
CVE-2016-4694
Description
The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue, a related issue to CVE-2016-5387.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlnvdMailing ListVendor Advisory
- lists.apple.com/archives/security-announce/2016/Sep/msg00009.htmlnvdMailing ListVendor Advisory
- support.apple.com/HT207170nvdVendor Advisory
- support.apple.com/HT207171nvdVendor Advisory
- www.securityfocus.com/bid/93060nvd
- www.securitytracker.com/id/1036853nvd
News mentions
0No linked articles in our index yet.