CVE Database
/

CVE-2012-2336

Back to search

CVE-2012-2336

Published: May 11, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2012:0721
vendor-advisory
x_refsource_SUSE
SUSE-SU-2012:0840
vendor-advisory
x_refsource_SUSE
49014
third-party-advisory
x_refsource_SECUNIA
SSRT100992
vendor-advisory
x_refsource_HP
HPSBMU02900
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now