Amazon Linux AMI : golang (ALAS-2016-731) (httpoxy)
Medium Nessus Plugin ID 93009
SynopsisThe remote Amazon Linux AMI host is missing a security update.
DescriptionAn input-validation flaw was discovered in the Go programming language built in CGI implementation, which set the environment variable 'HTTP_PROXY' using the incoming 'Proxy' HTTP-request header. The environment variable 'HTTP_PROXY' is used by numerous web clients, including Go's net/http package, to specify a proxy server to use for HTTP and, in some cases, HTTPS requests. This meant that when a CGI-based web application ran, an attacker could specify a proxy server which the application then used for subsequent outgoing requests, allowing a man-in-the-middle attack.
SolutionRun 'yum update golang' to update your system.