VDB

DEBIAN-CVE-2012-0053

DEBIAN-CVE-2012-0053 PUBLISHED

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

Affected Products

VendorProductVersions
Debian:11apache20, 0, 0
Debian:12apache20, 0, 0
Debian:13apache20, 0, 0
Debian:14apache20, 0, 0

Timeline

  • Jan 28, 2012 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›