PT-2012-5362 · Google+3 · Google Chrome+3
Raphael Geissert
·
Published
2012-09-07
·
Updated
2023-02-13
·
CVE-2012-4388
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PHP versions 5.4.0RC2 through 5.4.0
Description
The issue arises from the sapi header op function in main/SAPI.c, which fails to properly determine a pointer during checks for %0D sequences, allowing remote attackers to bypass an HTTP response-splitting protection mechanism. This can be achieved via a crafted URL and is related to improper interaction between the PHP header function and certain browsers, such as Internet Explorer and Google Chrome.
Recommendations
For PHP versions 5.4.0RC2 through 5.4.0, update to a version that properly fixes the issue, as the current fix is incorrect and based on an earlier vulnerability.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome
Internet Explorer
Php
Suse