Back

MEDIUM

php: buffer overflow flaw in apache_request_headers() in PHP 5.4.x

Published May 11, 2012

Description

Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of PHP as shipped with Red Hat Enterprise Linux 4, 5, or 6. This flaw only affects PHP 5.4.0 through 5.4.2.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 11, 2012
Updated Aug 6, 2024
Reserved Apr 19, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date May 8, 2012