Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-2335

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2012-2335
Last Modified 23 Jul 2013 05:39:19
Published 11 May 2012 06:15:48
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2012-2335

Summary

php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c component and a query string beginning with a +- sequence.

Vulnerable Systems

Application

  • Php 5.3.12

  • Php 5.4.2


References

CERT-VN - VU#520827

MISC - https://bugs.php.net/bug.php?id=61910

MISC - http://www.php.net/archive/2012.php#id2012-05-06-1

MISC - http://git.php.net/?p=php-src.git;a=blob;f=sapi/cgi/cgi_main.c;h=a7ac26f0#l1569

MISC - http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/

SECUNIA - 49014

SUSE - SUSE-SU-2012:0840

XF - php-phpwrapperfcgi-code-exec(75652)

HP - HPSBMU02900

HP - SSRT100992

Related Patches

Novell SUSE 2012:6316 apache2-mod_php5 security update for SLES 11 SP1 i586

Novell SUSE 2012:6316 apache2-mod_php5 security update for SLES 11 SP1 x86_64

Novell SUSE 2012:6440 apache2-mod_php53 security update for SLES 11 SP2 i586

Novell SUSE 2012:6440 apache2-mod_php53 security update for SLES 11 SP2 x86_64

Novell SUSE 2012:8133 apache2-mod_php5 security update for SLES 10 SP4 i586

Novell SUSE 2012:8133 apache2-mod_php5 security update for SLES 10 SP4 x86_64


Last Updated: 27 May 2016 10:56:29