CVE-2012-0021
28.01.2012, 04:05
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.EnginsightAffected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 2.2.17 |
| apache | http_server | 2.2.18 |
| apache | http_server | 2.2.19 |
| apache | http_server | 2.2.20 |
| apache | http_server | 2.2.21 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache2 |
| ||||||||||||||
| apache2-devel |
| ||||||||||||||
| apache2-doc |
| ||||||||||||||
| apache2-example-pages |
| ||||||||||||||
| apache2-prefork |
| ||||||||||||||
| apache2-utils |
| ||||||||||||||
| apache2-worker |
|
Common Weakness Enumeration
References