PHP 'main/SAPI.c' CVE-2012-4388 HTTP Header Injection Vulnerability
BID:55527
Info
PHP 'main/SAPI.c' CVE-2012-4388 HTTP Header Injection Vulnerability
| Bugtraq ID: | 55527 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-4388 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2012 12:00AM |
| Updated: | Aug 19 2013 08:37AM |
| Credit: | Mr. Tokumaru |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server for VMware 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE SUSE Linux Enterprise SDK 10 SP4 |
| Not Vulnerable: | |
Discussion
PHP 'main/SAPI.c' CVE-2012-4388 HTTP Header Injection Vulnerability
PHP is prone to a vulnerability that allows attackers to inject arbitrary headers through a URL.
By inserting arbitrary headers, attackers may be able to launch cross-site request-forgery, cross-site scripting, HTML-injection, and other attacks.
Note that this issue exists due to an incomplete fix for CVE-2011-1398 (BID 55297 PHP 'header()' HTTP Header Injection Vulnerability).
PHP 5.4.0RC2 through 5.4.0 are vulnerable.
PHP is prone to a vulnerability that allows attackers to inject arbitrary headers through a URL.
By inserting arbitrary headers, attackers may be able to launch cross-site request-forgery, cross-site scripting, HTML-injection, and other attacks.
Note that this issue exists due to an incomplete fix for CVE-2011-1398 (BID 55297 PHP 'header()' HTTP Header Injection Vulnerability).
PHP 5.4.0RC2 through 5.4.0 are vulnerable.
Exploit / POC
PHP 'main/SAPI.c' CVE-2012-4388 HTTP Header Injection Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
PHP 'main/SAPI.c' CVE-2012-4388 HTTP Header Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.