4.3

CVE-2012-4388

Exploit
The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1398.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version >= 5.3.0 < 5.3.11
Php ≫ Php Version 5.4.0 Update rc2
Canonical ≫ Ubuntu Linux Version 8.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 11.04
Canonical ≫ Ubuntu Linux Version 11.10
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Debian ≫ Debian Linux Version 6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.23% 0.897
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.ubuntu.com/usn/USN-1569-1
Third Party Advisory
http://article.gmane.org/gmane.comp.php.devel/70584
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00006.html
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2012/08/29/5
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2012/09/05/15
Third Party Advisory
Mailing List
http://www.securitytracker.com/id?1027463
Third Party Advisory
VDB Entry
https://bugs.php.net/bug.php?id=60227
Vendor Advisory
http://openwall.com/lists/oss-security/2012/09/02/1
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2012/09/07/3
Third Party Advisory
Mailing List
http://security-tracker.debian.org/tracker/CVE-2012-4388
Third Party Advisory
http://svn.php.net/viewvc/php/php-src/branches/PHP_5_4/main/SAPI.c?r1=323986&r2=323985&pathrev=323986
Patch
Vendor Advisory
Exploit