CVE-2012-0053
Last modified
CVE-2012-0053 is a vulnerability of currently unknown severity. protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.. EPSS estimates a 82.76% chance of exploitation in the next 30 days.
Description
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Apache | Http Server | >= 2.0.0, < 2.0.65 | — |
| Apache | Http Server | >= 2.2.0, < 2.2.22 | — |
| Debian | Debian Linux | 5.0 | — |
| Debian | Debian Linux | 6.0 | — |
| Debian | Debian Linux | 7.0 | — |
| Opensuse | Opensuse | 11.4 | — |
| Suse | Linux Enterprise Server | 10 | Sp4 |
| Suse | Linux Enterprise Software Development Kit | 10 | Sp4 |
| Redhat | Storage | 2.0 | — |
| Redhat | Enterprise Linux Desktop | 6.0 | — |
| Redhat | Enterprise Linux Eus | 6.2 | — |
| Redhat | Enterprise Linux Server | 6.0 | — |
| Redhat | Enterprise Linux Workstation | 6.0 | — |
| Redhat | Jboss Enterprise Web Server | 1.0.0 | — |
References
- http://httpd.apache.org/security/vulnerabilities_22.htmlVendor Advisory
- http://kb.juniper.net/JSA10585Third Party Advisory
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.htmlBroken Link, Mailing List
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=133294460209056&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=133494237717847&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=133951357207000&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=136441204617335&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0128.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0542.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0543.htmlThird Party Advisory
- http://secunia.com/advisories/48551Not Applicable
- http://support.apple.com/kb/HT5501Third Party Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1235454Patch, Vendor Advisory
- http://www.debian.org/security/2012/dsa-2405Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlThird Party Advisory
- http://www.securityfocus.com/bid/51706Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=785069Issue Tracking, Third Party Advisory
- http://httpd.apache.org/security/vulnerabilities_22.htmlVendor Advisory
- http://kb.juniper.net/JSA10585Third Party Advisory
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.htmlBroken Link, Mailing List
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=133294460209056&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=133494237717847&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=133951357207000&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=136441204617335&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0128.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0542.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0543.htmlThird Party Advisory
- http://secunia.com/advisories/48551Not Applicable
- http://support.apple.com/kb/HT5501Third Party Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1235454Patch, Vendor Advisory
- http://www.debian.org/security/2012/dsa-2405Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlThird Party Advisory
- http://www.securityfocus.com/bid/51706Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=785069Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-0053?
How severe is CVE-2012-0053?
How do I fix CVE-2012-0053?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-0047Cross-site scripting (XSS) vulnerability in Apache Wicket 1.…
- CVE-2012-0048OpenTTD 0.3.5 through 1.1.4 allows remote attackers to cause…
- CVE-2012-0049OpenTTD before 1.1.5 contains a Denial of Service (slow read…4.3
- CVE-2012-0050OpenSSL 0.9.8s and 1.0.0f does not properly support DTLS app…
- CVE-2012-0051Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remo…7.4
- CVE-2012-0052Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.…
- CVE-2012-0054libs/updater.py in GoLismero 0.6.3, and other versions befor…
- CVE-2012-0055OverlayFS in the Linux kernel before 3.0.0-16.28, as used in…7.8
- CVE-2012-0056The mem_write function in the Linux kernel before 3.2.2, whe…
- CVE-2012-0057PHP before 5.3.9 has improper libxslt security settings, whi…
- CVE-2012-0058The kiocb_batch_free function in fs/aio.c in the Linux kerne…5.5
- CVE-2012-0059A flaw was found in Spacewalk-backend. This information disc…4.9
Are you affected by CVE-2012-0053?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
