CVE-2012-0053 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 82.2% (pctl 100)
Patch early
A public exploit exists.
Description
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
| EPSS | 82.2% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-01-28 |
| Last modified | 2026-06-16 |
Affected (12)
| Vendor | Product |
|---|---|
| apache | http server |
| debian | debian linux |
| opensuse | opensuse |
| redhat | enterprise linux |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux server |
| redhat | enterprise linux workstation |
| redhat | jboss enterprise web server |
| redhat | storage |
| suse | linux enterprise server |
| suse | linux enterprise software development kit |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache - httpOnly Cookie Disclosure | 2012-01-31 |
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041
- http://httpd.apache.org/security/vulnerabilities_22.html
- http://kb.juniper.net/JSA10585
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.html
- http://marc.info/?l=bugtraq&m=133294460209056&w=2
- http://marc.info/?l=bugtraq&m=133494237717847&w=2
- http://marc.info/?l=bugtraq&m=133951357207000&w=2
- http://marc.info/?l=bugtraq&m=136441204617335&w=2
- http://rhn.redhat.com/errata/RHSA-2012-0128.html
- http://rhn.redhat.com/errata/RHSA-2012-0542.html
- http://rhn.redhat.com/errata/RHSA-2012-0543.html
- http://secunia.com/advisories/48551
- http://support.apple.com/kb/HT5501
- http://svn.apache.org/viewvc?view=revision&revision=1235454
- http://www.debian.org/security/2012/dsa-2405
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:012
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
→ the Explorer · watch your stack · NVD