CVE-2012-0053: Apache HTTP Server

Medium severity, CVSS 4.3. EPSS: 82.2% chance of exploitation in the next 30 days.

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

Affected products

  • Apache HTTP Server: from 2.0.0, before 2.0.65 (fixed in 2.0.65); from 2.2.0, before 2.2.22 (fixed in 2.2.22)
  • Debian Debian Linux: version 5.0 only; version 6.0 only; version 7.0 only
  • Opensuse Opensuse: version 11.4 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Eus: version 6.2 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Red Hat JBoss Enterprise Web Server: version 1.0.0 only
  • Red Hat Storage: version 2.0 only
  • Suse Linux Enterprise Server: version 10 only
  • Suse Linux Enterprise Software Development Kit: version 10 only

Published 2012-01-28. Last modified 2026-06-16.