← Back

CVE-2012-0807

nvd nist
Published: Jan 27, 2012Modified: Apr 29, 2026

JSON object

Loading...
5.1
Vector
AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploitability: 4.9 / Impact: 6.4
Source: NVD

Description

Stack-based buffer overflow in the suhosin_encrypt_single_cookie function in the transparent cookie-encryption feature in the Suhosin extension before 0.9.33 for PHP, when suhosin.cookie.encrypt and suhosin.multiheader are enabled, might allow remote attackers to execute arbitrary code via a long string that is used in a Set-Cookie HTTP header.

Affected (38)

1 product
Suhosin
Configuration A
38 vulnerable
Vulnerable SoftwareAffected Versions
Hardened Php
Up to 0.9.31
All versions
All versions
Version 0.9.0
Version 0.9.10
Version 0.9.11
Version 0.9.12
Version 0.9.13
Version 0.9.14
Version 0.9.15
Version 0.9.16
Version 0.9.17
Version 0.9.18
Version 0.9.19
Version 0.9.1
Version 0.9.20
Version 0.9.21
Version 0.9.22
Version 0.9.23
Version 0.9.24
Version 0.9.25
Version 0.9.26
Version 0.9.27
Version 0.9.28
Version 0.9.29
Version 0.9.2
Version 0.9.30
Version 0.9.3
Version 0.9.4
Version 0.9.5
Version 0.9.6.1
Version 0.9.6.2
Version 0.9.6.3
Version 0.9.6
Version 0.9.7
Version 0.9.8
Version 0.9.9.1
Version 0.9.9

References (18)

Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.