CVE-2012-0807: Hardened-PHP Suhosin

Medium severity, CVSS 5.1. EPSS: 3.5% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the suhosin_encrypt_single_cookie function in the transparent cookie-encryption feature in the Suhosin extension before 0.9.33 for PHP, when suhosin.cookie.encrypt and suhosin.multiheader are enabled, might allow remote attackers to execute arbitrary code via a long string that is used in a Set-Cookie HTTP header.

Affected products

  • Hardened-PHP Suhosin: any version; up to and including 0.9.31; version 0.9.0 only; version 0.9.1 only; version 0.9.2 only; version 0.9.3 only; …

Published 2012-01-27. Last modified 2026-06-16.