VDB
CVE-2012-2329
CVE-2012-2329
PUBLISHED
Deux vulnérabilités permettant d'exécuter du code arbitraire à distance ont été corrigées dans PHP. La première concernant l'implémentation CGI (CVE-2012-2311) impacte les versions 5.3 et 5.4 de PHP. La seconde, de type corruption mémoire (CVE-2012-2329), se situe dans la fonction <span class="textit">apache_request_headers()</span> et n'impacte que la version 5.4.
EPSS 62.30% · 99.1th percentile
Risk Scores
EPSS Score
62.30%
99.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PHP | PHP |
Timeline
- Sep 16, 2010 PoC Published
- May 9, 2012 CVE Published
- Sep 6, 2015 PoC Published
- Oct 9, 2020 PoC Published
- Feb 4, 2022 EPSS Score
- Apr 24, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 26, 2022 EPSS Score
- Aug 31, 2022 PoC Published
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://cert.ssi.gouv.fr/avis/CERTA-2012-AVI-267/ advisory
- http://www.php.net/archive/2012.php#id2012-05-08-1 advisory
- https://cert.ssi.gouv.fr/avis/CERTFR-2014-AVI-480/ advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10661 advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10657 advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10658 advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10659 advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10660 advisory