Vulnerability Name:

CVE-2012-0807 (CCN-72465)

Assigned:2012-01-19
Published:2012-01-19
Updated:2018-01-18
Summary:Stack-based buffer overflow in the suhosin_encrypt_single_cookie function in the transparent cookie-encryption feature in the Suhosin extension before 0.9.33 for PHP, when suhosin.cookie.encrypt and suhosin.multiheader are enabled, might allow remote attackers to execute arbitrary code via a long string that is used in a Set-Cookie HTTP header.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: FULLDISC
Type: Exploit
20120119 Advisory 01/2012: Suhosin PHP Extension Transparent Cookie Encryption Stack Buffer Overflow

Source: MITRE
Type: CNA
CVE-2012-0807

Source: SUSE
Type: UNKNOWN
SUSE-SU-2012:0411

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2012:0426

Source: SUSE
Type: UNKNOWN
SUSE-SU-2012:0472

Source: CCN
Type: Full-disclosure Mailing List, Thu, 19 Jan 2012 17:18:23 +0100
Suhosin PHP Extension Transparent Cookie Encryption Stack Buffer Overflow

Source: CCN
Type: SA47689
PHP Suhosin Extension Transparent Cookie Encryption Buffer Overflow Vulnerability

Source: SECUNIA
Type: UNKNOWN
48668

Source: CCN
Type: Hardened PHP Project Web site
Suhosin

Source: MLIST
Type: UNKNOWN
[oss-security] 20120124 Re: CVE requests: Suhosin extension / as31

Source: MLIST
Type: UNKNOWN
[oss-security] 20120124 CVE requests: Suhosin extension / as31

Source: CCN
Type: OSVDB ID: 78514
Suhosin Extension for PHP Transparent Cookie Encryption Remote Overflow

Source: CCN
Type: BID-51574
Suhosin Extension Transparent Cookie Encryption Stack Buffer Overflow Vulnerability

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=783350

Source: XF
Type: UNKNOWN
suhosin-extension-cookie-bo(72465)

Source: CCN
Type: Suhosin GIT Repository
Suhosin

Source: CONFIRM
Type: Exploit, Patch
https://github.com/stefanesser/suhosin/commit/73b1968ee30f6d9d2dae497544b910e68e114bfa

Vulnerable Configuration:Configuration 1:
  • cpe:/a:hardened-php:suhosin:*:beta_2006.09.07:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:*:beta_2006.09.09:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.0:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.1:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.2:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.3:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.4:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.5:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.6:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.7:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.8:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.9:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.9.1:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.10:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.11:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.12:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.13:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.14:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.15:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.16:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.17:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.18:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.19:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.20:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.21:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.22:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.23:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.24:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.25:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.26:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.27:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.28:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.29:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:0.9.30:*:*:*:*:*:*:*
  • OR cpe:/a:hardened-php:suhosin:*:*:*:*:*:*:*:* (Version <= 0.9.31)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20120807
    V
    CVE-2012-0807
    2022-05-20
    oval:org.opensuse.security:def:42273
    P
    Security update for glib2 (Low)
    2022-04-28
    oval:org.opensuse.security:def:31334
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:33049
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:32218
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:26163
    P
    Security update for bind (Important)
    2021-11-11
    oval:org.opensuse.security:def:31700
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:26148
    P
    Security update for javapackages-tools, javassist, mysql-connector-java, protobuf, python-python-gflags (Important)
    2021-10-15
    oval:org.opensuse.security:def:26134
    P
    Security update for the Linux Kernel (Important)
    2021-09-23
    oval:org.opensuse.security:def:32162
    P
    Security update for libcares2 (Important)
    2021-08-16
    oval:org.opensuse.security:def:26099
    P
    Security update for libsndfile (Critical)
    2021-08-05
    oval:org.opensuse.security:def:26095
    P
    Security update for glibc (Moderate)
    2021-07-27
    oval:org.opensuse.security:def:32153
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-07-27
    oval:org.opensuse.security:def:26088
    P
    Security update for the Linux Kernel (Important)
    2021-07-14
    oval:org.opensuse.security:def:31643
    P
    Security update for apache2 (Important)
    2021-06-17
    oval:org.opensuse.security:def:31638
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:42493
    P
    apache2-mod_php53-5.3.17-0.41.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36086
    P
    apache2-mod_php53-5.3.17-0.41.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36538
    P
    php53-devel-5.3.17-0.41.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32109
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:26046
    P
    Security update for libxml2 (Moderate)
    2021-05-05
    oval:org.opensuse.security:def:32087
    P
    Security update for cups (Important)
    2021-04-30
    oval:org.opensuse.security:def:26212
    P
    Security update for python3 (Moderate)
    2021-03-19
    oval:org.opensuse.security:def:32267
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:31345
    P
    Security update for krb5-appl (Important)
    2021-02-19
    oval:org.opensuse.security:def:26192
    P
    Security update for php72 (Important)
    2021-02-17
    oval:org.opensuse.security:def:31333
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:26087
    P
    Security update for sudo (Important)
    2021-01-26
    oval:org.opensuse.security:def:33010
    P
    Security update for java-1_8_0-ibm (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:26061
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:32830
    P
    Security update for python (Important)
    2020-12-11
    oval:org.opensuse.security:def:25977
    P
    Security update for openssl-1_1 (Important)
    2020-12-10
    oval:org.opensuse.security:def:32006
    P
    Security update for mutt (Important)
    2020-12-07
    oval:org.opensuse.security:def:35866
    P
    apache2-mod_php53-5.3.17-0.13.7 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:26314
    P
    Security update for iperf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27084
    P
    apache2-mod_php53 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25417
    P
    Security update for postgresql, postgresql96, postgresql10 and postgresql12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26513
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:32372
    P
    Security update for tcpdump (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25758
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:26819
    P
    ruby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31551
    P
    Security update for shim
    2020-12-01
    oval:org.opensuse.security:def:25711
    P
    Security update for python-aws-sam-translator, python-boto3, python-botocore, python-cfn-lint, python-jsonschema, python-nose2, python-parameterized, python-pathlib2, python-pytest-cov, python-requests, python-s3transfer (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31999
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:31553
    P
    Security update for sqlite3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32791
    P
    syslog-ng on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31919
    P
    Security update for ghostscript-library (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26411
    P
    Security update for go (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26372
    P
    Recommended update for geotiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32306
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25620
    P
    Security update for ovmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26766
    P
    libsamplerate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27536
    P
    php53-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25636
    P
    Security update for libproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:31787
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26830
    P
    t1lib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31770
    P
    Security update for MozillaFirefox, mozilla-nss, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:26353
    P
    Security update for tor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25428
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:26664
    P
    aaa_base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25842
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26863
    P
    apache2-mod_jk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25839
    P
    Security update for gimp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32048
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31564
    P
    Security update for squid3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26265
    P
    Security update for guile (Low)
    2020-12-01
    oval:org.opensuse.security:def:27049
    P
    unzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25416
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26429
    P
    Security update for keepalived (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32328
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25701
    P
    Security update for libexif (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26805
    P
    perl-Tk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31419
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25647
    P
    Security update for freetype2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31943
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26865
    P
    apache2-mod_php53 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31552
    P
    Security update for socat (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31862
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26367
    P
    Security update for MozillaThunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26291
    P
    Security update for python-reportlab (Important)
    2020-12-01
    oval:org.opensuse.security:def:25492
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26717
    P
    gzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25993
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27501
    P
    libwmf on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25635
    P
    Security update for tigervnc (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25920
    P
    Security update for gstreamer-plugins-base (Moderate)
    2020-12-01
    oval:com.ubuntu.precise:def:20120807000
    V
    CVE-2012-0807 on Ubuntu 12.04 LTS (precise) - medium.
    2012-01-26
    BACK
    hardened-php suhosin * beta_2006.09.07
    hardened-php suhosin * beta_2006.09.09
    hardened-php suhosin 0.9.0
    hardened-php suhosin 0.9.1
    hardened-php suhosin 0.9.2
    hardened-php suhosin 0.9.3
    hardened-php suhosin 0.9.4
    hardened-php suhosin 0.9.5
    hardened-php suhosin 0.9.6
    hardened-php suhosin 0.9.6.1
    hardened-php suhosin 0.9.6.2
    hardened-php suhosin 0.9.6.3
    hardened-php suhosin 0.9.7
    hardened-php suhosin 0.9.8
    hardened-php suhosin 0.9.9
    hardened-php suhosin 0.9.9.1
    hardened-php suhosin 0.9.10
    hardened-php suhosin 0.9.11
    hardened-php suhosin 0.9.12
    hardened-php suhosin 0.9.13
    hardened-php suhosin 0.9.14
    hardened-php suhosin 0.9.15
    hardened-php suhosin 0.9.16
    hardened-php suhosin 0.9.17
    hardened-php suhosin 0.9.18
    hardened-php suhosin 0.9.19
    hardened-php suhosin 0.9.20
    hardened-php suhosin 0.9.21
    hardened-php suhosin 0.9.22
    hardened-php suhosin 0.9.23
    hardened-php suhosin 0.9.24
    hardened-php suhosin 0.9.25
    hardened-php suhosin 0.9.26
    hardened-php suhosin 0.9.27
    hardened-php suhosin 0.9.28
    hardened-php suhosin 0.9.29
    hardened-php suhosin 0.9.30
    hardened-php suhosin *