LWN.net Logo

php: header injection

Package(s):PHP5 CVE #(s):CVE-2011-1398 CVE-2011-4388
Created:September 13, 2012 Updated:February 28, 2013
Description: From the Ubuntu advisory:

It was discovered that PHP incorrectly handled certain character sequences when applying HTTP response-splitting protection. A remote attacker could create a specially-crafted URL and inject arbitrary headers. (CVE-2011-1398, CVE-2012-4388)

Alerts:
SUSE SUSE-SU-2012:1156-1 2012-09-13
SUSE SUSE-SU-2012:1156-2 2012-09-14
Ubuntu USN-1569-1 2012-09-17
SUSE SUSE-SU-2012:1210-1 2012-09-18
Gentoo 201209-03 2012-09-23
Red Hat RHSA-2013:0514-02 2013-02-21
Oracle ELSA-2013-0514 2013-02-28
Scientific Linux SL-php-20130228 2013-02-28
CentOS CESA-2013:0514 2013-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds