php: header() injection detection bypass (incorrect fix for CVE-2011-1398)
Published Sep 7, 2012
4.3
MEDIUMCVSS 2.0
EPSS 4.23%
Description
The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1398.
Affected products
No data.
Configuration 2
- 8.04
- 10.04
- 11.04
- 11.10
- 12.04
Configuration 3
- 6.0
No data.
Red Hat Enterprise Linux 5
php
Not affected
Red Hat Enterprise Linux 5
php53
Not affected
Red Hat Enterprise Linux 6
php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | php | Not affected | n/a |
| Red Hat Enterprise Linux 5 | php53 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | php | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of php as shipped with Red Hat Enterprise Linux 5 and 6, and the version of php53 as shipped with Red Hat Enterprise Linux 5 as they did not include the upstream commit 322263 that introduced this issue.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.23% (0.04225) | 90.69th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.23% (0.04225) | 89.68th | v5 (v2026.06.15) |
| Jan 20, 2026 | 2.19% (0.02187) | 83.94th | v4 (v2025.03.14) |
| Aug 24, 2025 | 0.94% (0.00942) | 75.30th | v4 (v2025.03.14) |
| Mar 30, 2025 | 3.08% (0.03076) | 85.56th | v4 (v2025.03.14) |
| Mar 29, 2025 | 5.04% (0.05044) | 82.55th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.08% (0.03076) | 85.85th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.15% (0.00151) | 52.75th | v3 (v2023.03.01) |
| May 8, 2023 | 0.15% (0.00151) | 49.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.20% (0.00198) | 55.85th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.96% (0.01955) | 78.47th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.96% (0.01955) | 76.59th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.96% (0.01955) | 55.71th | v2 (v2022.01.01) |
References (15)
- http://article.gmane.org/gmane.comp.php.devel/70584 mailing-listx_refsource_MLISTBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2012/08/29/5 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2012/09/02/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2012/09/05/15 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2012/09/07/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://security-tracker.debian.org/tracker/CVE-2012-4388 x_refsource_CONFIRMThird Party Advisory
- http://svn.php.net/viewvc/php/php-src/branches/PHP_5_4/main/SAPI.c?r1=323986&r2=323985&pathrev=323986 x_refsource_CONFIRMExploitPatchVendor Advisory
- http://www.securitytracker.com/id?1027463 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-1569-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2012-4388 Vendor Advisory
- https://bugs.php.net/bug.php?id=60227 x_refsource_MISCVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=854184 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2012-4388
- https://www.cve.org/CVERecord?id=CVE-2012-4388
Change history (0)
No recorded changes yet.