← back
CVE-2012-2329

CVE-2012-2329

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 63%
from disclosure to weapon37 days
Published on NVDMay 11
1st PoC+37d
metasploitMay 8
exploitation probability
63%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.