FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-0053

This CVE name corresponds to:

Entered Topic
2012-01-31 apache -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-0053
Phase Assigned(20111207)

Description

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

References

Source Reference
CONFIRM http://httpd.apache.org/security/vulnerabilities_22.html
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1235454
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=785069
CONFIRM http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html
CONFIRM http://support.apple.com/kb/HT5501
CONFIRM http://kb.juniper.net/JSA10585
CONFIRM http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
APPLE APPLE-SA-2012-09-19-2
HP HPSBMU02786
HP SSRT100877
HP HPSBST02848
HP SSRT101112
MANDRIVA MDVSA-2013:150
REDHAT RHSA-2012:0128
SUSE openSUSE-SU-2012:0314
BID 51706
SECUNIA 48551