CVE-2012-0053

N/A Unknown
Published: January 28, 2012 Modified: April 29, 2026
View on NVD

Description

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://httpd.apache.org/security/vulnerabilities_22.html
Source: secalert@redhat.com
Vendor Advisory
http://kb.juniper.net/JSA10585
Source: secalert@redhat.com
Third Party Advisory
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html
Source: secalert@redhat.com
Broken Link Mailing List
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html
Source: secalert@redhat.com
Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.html
Source: secalert@redhat.com
Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=133294460209056&w=2
Source: secalert@redhat.com
Issue Tracking Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=133494237717847&w=2
Source: secalert@redhat.com
Issue Tracking Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=133951357207000&w=2
Source: secalert@redhat.com
Issue Tracking Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=136441204617335&w=2
Source: secalert@redhat.com
Issue Tracking Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0128.html
Source: secalert@redhat.com
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0542.html
Source: secalert@redhat.com
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0543.html
Source: secalert@redhat.com
Third Party Advisory
http://secunia.com/advisories/48551
Source: secalert@redhat.com
Not Applicable
http://support.apple.com/kb/HT5501
Source: secalert@redhat.com
Third Party Advisory
http://svn.apache.org/viewvc?view=revision&revision=1235454
Source: secalert@redhat.com
Patch Vendor Advisory
http://www.debian.org/security/2012/dsa-2405
Source: secalert@redhat.com
Third Party Advisory
http://www.securityfocus.com/bid/51706
Source: secalert@redhat.com
Third Party Advisory VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=785069
Source: secalert@redhat.com
Issue Tracking Third Party Advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://httpd.apache.org/security/vulnerabilities_22.html
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://kb.juniper.net/JSA10585
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Mailing List
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.html
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=133294460209056&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=133494237717847&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=133951357207000&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=136441204617335&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0128.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0542.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0543.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://secunia.com/advisories/48551
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
http://support.apple.com/kb/HT5501
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://svn.apache.org/viewvc?view=revision&revision=1235454
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.debian.org/security/2012/dsa-2405
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2012:012
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.securityfocus.com/bid/51706
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=785069
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Third Party Advisory

90 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
82.8%
100th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

opensuse debian redhat apache suse