CVE-2012-4388
published 2012-09-07CVE-2012-4388: The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
4.23%
89.9th percentile
The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1398.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| php | php | — | — |
| php | php | >= 5.3.0 < 5.3.11 | 5.3.11 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2012-09-17·CVSS 4.3
CVE-2011-1398 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that PHP incorrectly handled certain character sequences
when applying HTTP response-splitting protection. A remote attacker could
create a specially-crafted URL and inject arbitrary headers.
(CVE-2011-1398, CVE-2012-4388)
It was discovered that PHP incorrectly handled directories with a large
number of files. This could allow a remote attacker to execute arbitrary
code with the privileges of the web server, or to perform a denial of
service. (CVE-2012-2688)
It was discovered that PHP incorrectly parsed certain PDO prepared
statements. A remote attacker could use this flaw to cause PHP to crash,
leading to a denial of service. (CVE-2012-3450)
Instructions: In general, a standard system upd
Red Hat
php: header() injection detection bypass (incorrect fix for CVE-2011-1398)
vendor_redhat·2012-09-02·CVSS 4.3
CVE-2012-4388 [MEDIUM] php: header() injection detection bypass (incorrect fix for CVE-2011-1398)
php: header() injection detection bypass (incorrect fix for CVE-2011-1398)
The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1398.
Statement: Not vulnerable. This issue did not affect the versions of php as shipped with Red Hat Enterprise Linux 5 and 6, and the version of php53 as shipped with Red Hat Enterprise Linux 5 as they did not include the
GHSA
GHSA-78pr-9xh4-8h52: The sapi_header_op function in main/SAPI
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2012-4388 [MEDIUM] CWE-20 GHSA-78pr-9xh4-8h52: The sapi_header_op function in main/SAPI
The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1398.
No detection rules found.
No public exploits indexed.
http://article.gmane.org/gmane.comp.php.devel/70584http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00006.htmlhttp://openwall.com/lists/oss-security/2012/08/29/5http://openwall.com/lists/oss-security/2012/09/02/1http://openwall.com/lists/oss-security/2012/09/05/15http://openwall.com/lists/oss-security/2012/09/07/3http://security-tracker.debian.org/tracker/CVE-2012-4388http://svn.php.net/viewvc/php/php-src/branches/PHP_5_4/main/SAPI.c?r1=323986&r2=323985&pathrev=323986http://www.securitytracker.com/id?1027463http://www.ubuntu.com/usn/USN-1569-1https://bugs.php.net/bug.php?id=60227http://article.gmane.org/gmane.comp.php.devel/70584http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00006.htmlhttp://openwall.com/lists/oss-security/2012/08/29/5http://openwall.com/lists/oss-security/2012/09/02/1http://openwall.com/lists/oss-security/2012/09/05/15http://openwall.com/lists/oss-security/2012/09/07/3http://security-tracker.debian.org/tracker/CVE-2012-4388http://svn.php.net/viewvc/php/php-src/branches/PHP_5_4/main/SAPI.c?r1=323986&r2=323985&pathrev=323986http://www.securitytracker.com/id?1027463http://www.ubuntu.com/usn/USN-1569-1https://bugs.php.net/bug.php?id=60227
2012-09-07
Published