LOW · 2.6

CVE-2012-0021

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, wh...

Vulnerability Description

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.

CVSS Score

2.6

LOW

AV:N/AC:H/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
ApacheHttp Server2.2.17

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-0021?

CVE-2012-0021 is a vulnerability with a CVSS score of 2.6 (LOW). The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, wh...

How severe is CVE-2012-0021?

CVE-2012-0021 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-0021?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server.