Request Tracker CVE-2013-3372 HTTP Header Injection Vulnerability
BID:60105
Info
Request Tracker CVE-2013-3372 HTTP Header Injection Vulnerability
| Bugtraq ID: | 60105 |
| Class: | Design Error |
| CVE: |
CVE-2013-3372 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2013 12:00AM |
| Updated: | May 22 2013 12:00AM |
| Credit: | Dominic Hargreaves |
| Vulnerable: |
Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Bestpractical RT 3.8.16 Bestpractical RT 3.8.15 Bestpractical RT 3.8.11 Bestpractical RT 3.8.10 Bestpractical RT 3.8.8 Bestpractical RT 3.8.6 Bestpractical RT 3.8.5 Bestpractical RT 3.8.4 Bestpractical RT 3.8.2 Bestpractical RT 4.0.8 Bestpractical RT 4.0.6 Bestpractical RT 4.0.12 Bestpractical RT 4.0.10 Bestpractical RT 4.0 Bestpractical RT 3.8.9 Bestpractical RT 3.8.12 Bestpractical RT 3.8 |
| Not Vulnerable: |
Bestpractical RT 3.8.17 Bestpractical RT 4.0.13 |
Discussion
Request Tracker CVE-2013-3372 HTTP Header Injection Vulnerability
Request Tracker is prone to an HTTP-header-injection vulnerability.
An attacker may exploit this issue to inject arbitrary HTTP headers into a server response.
By inserting arbitrary headers into an HTTP response, attackers may be able to launch cross-site scripting attacks.
Request Tracker is prone to an HTTP-header-injection vulnerability.
An attacker may exploit this issue to inject arbitrary HTTP headers into a server response.
By inserting arbitrary headers into an HTTP response, attackers may be able to launch cross-site scripting attacks.
Exploit / POC
Request Tracker CVE-2013-3372 HTTP Header Injection Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution / Fix
Request Tracker CVE-2013-3372 HTTP Header Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Request Tracker CVE-2013-3372 HTTP Header Injection Vulnerability
References:
References:
- [rt-announce] Security vulnerabilities in RT (Best Practical Solutions)
- Request Tracker 3.8.17 Release Notes (Best Practical Solutions)
- Request Tracker 4.0.13 Release Notes (Best Practical Solutions)
- Request Tracker Homepage (Best Practical Solutions)
- DSA-2670-1 request-tracker3.8 -- several vulnerabilities (Debian )