Date: Thu, 8 Dec 2016 16:00:04 +0100 From: Casper Thomsen <ct@...arhaus.com> To: oss-security@...ts.openwall.com Subject: Re: Ruby:HTTP Header injection in 'net/http' On Sat, Jun 25, 2016 at 6:18 AM, redrain root <rootredrain@...il.com> wrote: > I would like to report a HTTP Header injection vulnerability in > 'net/http' that allows attackers to inject arbitrary headers in > request even create a new evil request. By the way, this was fixed in Excon back then. https://github.com/excon/excon/compare/4aa6548313188f3fa6ba6f556f49aead107b5881...107111759c945d2cac9b57ba5716e1b9a9055126 Regards, -- Casper Thomsen
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.