PT-2012-5362 · Google+3 · Google Chrome+3

Raphael Geissert

·

Published

2012-09-07

·

Updated

2023-02-13

·

CVE-2012-4388

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions 5.4.0RC2 through 5.4.0
Description The issue arises from the sapi header op function in main/SAPI.c, which fails to properly determine a pointer during checks for %0D sequences, allowing remote attackers to bypass an HTTP response-splitting protection mechanism. This can be achieved via a crafted URL and is related to improper interaction between the PHP header function and certain browsers, such as Internet Explorer and Google Chrome.
Recommendations For PHP versions 5.4.0RC2 through 5.4.0, update to a version that properly fixes the issue, as the current fix is incorrect and based on an earlier vulnerability.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2012-4388

Affected Products

Google Chrome
Internet Explorer
Php
Suse