CVE-2012-4388

high

Description

The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1398.

References

https://bugs.php.net/bug.php?id=60227

http://www.ubuntu.com/usn/USN-1569-1

http://www.securitytracker.com/id?1027463

http://security-tracker.debian.org/tracker/CVE-2012-4388

http://openwall.com/lists/oss-security/2012/09/07/3

http://openwall.com/lists/oss-security/2012/09/05/15

http://openwall.com/lists/oss-security/2012/09/02/1

http://openwall.com/lists/oss-security/2012/08/29/5

http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00006.html

Details

Source: Mitre, NVD

Published: 2012-09-07

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: High