Attacker Value
Unknown
(1 user assessed)
Exploitability
Unknown
(1 user assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2012-2329 PHP Apache Request Headers

Disclosure Date: May 11, 2012
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.

Add Assessment

1
Technical Analysis


”`

References

http://www.php.net/ChangeLog-5.php#5.4.3
Fixed bug #61807 Buffer Overflow in apache_request_headers, CVE-2012-2329. => Bug private at the moment of writing

http://www.securityfocus.com/bid/53455

Redhat, include patches:
https://bugzilla.redhat.com/show_bug.cgi?id=820000

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • php

Products

  • php 5.4.0,
  • php 5.4.1,
  • php 5.4.2

Additional Info

Technical Analysis