CVE-2012-2329: PHP
Medium severity, CVSS 5.0. EPSS: 62.3% chance of exploitation in the next 30 days.
Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.
Affected products
- PHP PHP: version 5.4.0 only; version 5.4.1 only; version 5.4.2 only
Published 2012-05-11. Last modified 2026-06-16.