CVE-2012-0807
Published Jan 27, 2012
Last updated 7 years ago
Overview
- Description
- Stack-based buffer overflow in the suhosin_encrypt_single_cookie function in the transparent cookie-encryption feature in the Suhosin extension before 0.9.33 for PHP, when suhosin.cookie.encrypt and suhosin.multiheader are enabled, might allow remote attackers to execute arbitrary code via a long string that is used in a Set-Cookie HTTP header.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.1
- Impact score
- 6.4
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-119
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:hardened-php:suhosin:*:beta_2006.09.07:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B1CF1F8-4A6B-4ABA-A07D-0E58B633138A" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:*:beta_2006.09.09:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3ED57AA4-0920-488E-A842-B44B86D230D3" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6A6A023-FAD1-4841-8C9E-F339B36BE1C2", "versionEndIncluding": "0.9.31" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0DFBFC80-CFD9-4D06-9E6D-F500059D776D" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B341570D-1782-4BB4-9833-68B477B05A39" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8F947E4-03FD-49B1-A19B-41D8A0A9EE17" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE8BB71D-DC96-466B-B44C-D43E5EB93923" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "207C8834-AFEA-4CEA-9A57-248F9B3A423C" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4AA1DEA9-AE84-4C38-9B57-FC4D8E267E14" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54294700-3713-4BB4-A0B1-167180736EA5" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D7C8553-13ED-473A-A664-641AE1D1CDCB" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8DC790A5-234E-4196-9099-19483FC5E946" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C0FF74F-B3A3-4441-8030-4547DDC0F4F7" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A65EAA2-67E7-4ADE-BEB9-37C4408F017B" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "341EF0C2-F73E-497D-8222-850E136A2CF2" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C02B1956-4F95-4F5D-BEE3-6E7CC3FAAD7C" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3192F3B1-81CF-43FE-AFA0-38E229F6C4D2" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AC3479B9-3430-47EA-990D-A9C5EE43B617" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AAEF53E2-F916-4B24-9923-FBAE0042721C" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "84A630C4-4CB1-4398-8B5E-1A1DC9598641" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BB05D8E0-2125-4596-BBAB-535343D149A4" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FDCFA3A0-FE1A-4F39-A3DB-24980D038AE7" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A88391C1-106B-4CC8-AB31-35191E7ABD35" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A7E45CD-45E9-4EC7-B995-DA259E5D50DE" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "572A8B49-1A01-4474-B8B4-0F72A1284924" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0755C35B-B34F-4F6C-9144-3370FD192E55" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C416FAFE-6CD9-41D1-B39F-D6BB6DC8A4A6" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A713D13B-1368-4392-9A96-352976A2C37B" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD345611-721B-4E0F-AA39-156FBC42129B" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5A19E0A-1BD8-47E4-954A-6CDD3C401342" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.23:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E4B7854-3D57-4296-9A4F-2239E055D06C" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.24:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF0BE10B-0654-4E5B-B766-90AD2D6929FD" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.25:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDC9AC17-D05F-4DFD-8C77-99ABC4BDB87B" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.26:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EEF75C23-7A2B-4DA3-8B80-44CBED2A8257" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.27:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "07D377C4-6051-4DB1-81BF-C4F358DA636B" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.28:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A978BC6A-7432-4A27-8F31-367566B76F9E" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.29:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5521C707-4412-4090-A5C1-9F5D8654A1D2" }, { "criteria": "cpe:2.3:a:hardened-php:suhosin:0.9.30:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C9FB2F06-B265-4C58-9705-31336AE50CE3" } ], "operator": "OR" } ] } ]