Apache HTTP Server "httpOnly" Cookie Information Leakage Vulnerability
Release date:
Updated on:
Affected Systems:
Apache Group Apache HTTP Server 2.2.x
Unaffected system:
Apache Group Apache HTTP Server 2.2.22-dev
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51706
Cve id: CVE 2012-0053
Apache HTTP Server is an open-source Web Server of the Apache Software Foundation and can be run in most computer operating systems.
Apache HTTP Server has the Cookie information leakage vulnerability in the implementation of default error responses to status code 400. After successful exploitation, attackers can obtain sensitive information.
<* Source: Norman Hippert
Link: http://httpd.apache.org/security/vulnerabilities_22.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/