Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-0053


protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.


Published

2012-01-28T04:05:00.797

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache http_server < 2.0.65 Yes
Application apache http_server < 2.2.22 Yes
Operating System debian debian_linux 5.0 Yes
Operating System debian debian_linux 6.0 Yes
Operating System debian debian_linux 7.0 Yes
Operating System opensuse opensuse 11.4 Yes
Operating System suse linux_enterprise_server 10 Yes
Operating System suse linux_enterprise_software_development_kit 10 Yes
Application redhat storage 2.0 Yes
Operating System redhat enterprise_linux_desktop 6.0 Yes
Operating System redhat enterprise_linux_eus 6.2 Yes
Operating System redhat enterprise_linux_server 6.0 Yes
Operating System redhat enterprise_linux_workstation 6.0 Yes
Application redhat jboss_enterprise_web_server 1.0.0 Yes
Operating System redhat enterprise_linux 5.0 No
Operating System redhat enterprise_linux 6.0 No

References