Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-0053

Опубликовано: 28 янв. 2012
Источник: ubuntu
Приоритет: medium
EPSS Высокий
CVSS2: 4.3

Описание

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

РелизСтатусПримечание
devel

not-affected

2.2.22-1ubuntu1
hardy

released

2.2.8-1ubuntu0.23
lucid

released

2.2.14-5ubuntu8.8
maverick

released

2.2.16-1ubuntu3.5
natty

released

2.2.17-1ubuntu1.5
oneiric

released

2.2.20-1ubuntu1.2
upstream

needs-triage

Показывать по

EPSS

Процентиль: 99%
0.74639
Высокий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 13 лет назад

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

nvd
больше 13 лет назад

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

debian
больше 13 лет назад

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not pro ...

github
больше 3 лет назад

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

oracle-oval
больше 13 лет назад

ELSA-2012-0323: httpd security update (MODERATE)

EPSS

Процентиль: 99%
0.74639
Высокий

4.3 Medium

CVSS2