Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <CAHzNyaB1R5s4PN3v6DgZori6Txv6tV_6WOgkcjWmLpMYafvgYQ@mail.gmail.com>
Date: Thu, 8 Dec 2016 16:00:04 +0100
From: Casper Thomsen <ct@...arhaus.com>
To: oss-security@...ts.openwall.com
Subject: Re: Ruby:HTTP Header injection in 'net/http'

On Sat, Jun 25, 2016 at 6:18 AM, redrain root <rootredrain@...il.com> wrote:
> I would like to report a HTTP Header injection vulnerability in
> 'net/http' that allows attackers to inject arbitrary headers in
> request even create a new evil request.

By the way, this was fixed in Excon back then.

https://github.com/excon/excon/compare/4aa6548313188f3fa6ba6f556f49aead107b5881...107111759c945d2cac9b57ba5716e1b9a9055126

Regards,
-- 
Casper Thomsen

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.