PT-2012-5362 · Google+3 · Google Chrome+3

·

CVE-2012-4388

·

Publicado

2012-09-07

·

Atualizado

2023-02-13

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions 5.4.0RC2 through 5.4.0
Description The issue arises from the sapi header op function in main/SAPI.c, which fails to properly determine a pointer during checks for %0D sequences, allowing remote attackers to bypass an HTTP response-splitting protection mechanism. This can be achieved via a crafted URL and is related to improper interaction between the PHP header function and certain browsers, such as Internet Explorer and Google Chrome.
Recommendations For PHP versions 5.4.0RC2 through 5.4.0, update to a version that properly fixes the issue, as the current fix is incorrect and based on an earlier vulnerability.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-4388

Produtos afetados

Google Chrome
Internet Explorer
Php
Suse