CVE-2012-0807

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
27/01/2012
Last modified:
11/04/2025

Description

Stack-based buffer overflow in the suhosin_encrypt_single_cookie function in the transparent cookie-encryption feature in the Suhosin extension before 0.9.33 for PHP, when suhosin.cookie.encrypt and suhosin.multiheader are enabled, might allow remote attackers to execute arbitrary code via a long string that is used in a Set-Cookie HTTP header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hardened-php:suhosin:*:beta_2006.09.07:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:*:beta_2006.09.09:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:*:*:*:*:*:*:*:* 0.9.31 (including)
cpe:2.3:a:hardened-php:suhosin:0.9.0:*:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:0.9.1:*:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:0.9.3:*:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:0.9.4:*:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:0.9.5:*:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:0.9.6:*:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:0.9.6.1:*:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:0.9.6.2:*:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:0.9.6.3:*:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:0.9.7:*:*:*:*:*:*:*
cpe:2.3:a:hardened-php:suhosin:0.9.8:*:*:*:*:*:*:*