PT-2012-2266 · Apache+4 · Apache Http Server+4

Publicado

2012-01-23

·

Atualizado

2024-06-15

·

CVE-2012-0053

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.2.x through 2.2.21
Description The issue allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a long or malformed header in conjunction with crafted web script, specifically when the server constructs Bad Request (400) error documents without proper restriction of header information. This flaw could be used by an attacker to expose "httpOnly" cookies when no custom ErrorDocument is specified.
Recommendations For Apache HTTP Server versions 2.2.x through 2.2.21, consider specifying a custom ErrorDocument for status code 400 to prevent exposure of "httpOnly" cookies. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CESA-2012_0128
CVE-2012-0053
DSA-2405-1
HPSBUX02761
OPENSUSE-SU-2024:10268-1
RHSA-2012:0128
RHSA-2012:0323
RHSA-2012:0542
RHSA-2012_0128
RHSA-2012_0323

Produtos afetados

Apache Http Server
Centos
Hp-Ux
Red Hat
Suse