Stack-based buffer overflow in the suhosin_encrypt_single_cookie function in the transparent cookie-encryption feature in the Suhosin extension before 0.9.33 for PHP, when suhosin.cookie.encrypt and suhosin.multiheader are enabled, might allow remote attackers to execute arbitrary code via a long string that is used in a Set-Cookie HTTP header.
CVSS Details
- CVSS 3.1 Base Score: 5.6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-php/suhosin.Upgrade www-apps/egroupware.Upgrade net-im/gg-transport.Upgrade sys-cluster/ganglia.Upgrade x11-libs/vte.Upgrade net-analyzer/lft.Upgrade x11-misc/slock. | Oct 30, 2017 | Jan 26, 2012 |
| Suse | — | Upgrade php53-domUpgrade php53-fastcgiUpgrade php53-xmlrpcUpgrade php53-exifUpgrade php53-opensslUpgrade php53-tokenizerUpgrade php53-zlibUpgrade php53-intlUpgrade php53-bcmathUpgrade php53-xmlwriterUpgrade apache2-mod_php53Upgrade php53-xslUpgrade php53-jsonUpgrade php53-pspellUpgrade php53-dbaUpgrade php53-bz2Upgrade php53-snmpUpgrade php53-ctypeUpgrade php53-gmpUpgrade php53-develUpgrade php53Upgrade php53-pgsqlUpgrade php53-pcntlUpgrade php53-pearUpgrade php53-gettextUpgrade php53-ldapUpgrade php53-sqliteUpgrade php53-wddxUpgrade php53-zipUpgrade php53-readlineUpgrade php53-imapUpgrade php53-sysvshmUpgrade php53-soapUpgrade php53-pdoUpgrade php53-suhosinUpgrade php53-posixUpgrade php53-gdUpgrade php53-sysvsemUpgrade php53-sysvmsgUpgrade php53-curlUpgrade php53-mbstringUpgrade php53-mysqlUpgrade php53-ftpUpgrade php53-mcryptUpgrade php53-xmlreaderUpgrade php53-calendarUpgrade php53-iconvUpgrade php53-socketsUpgrade php53-shmopUpgrade php53-odbcUpgrade php53-tidyUpgrade php53-fileinfo | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub