CVE-2012-0021

low
Published 2012-01-28 · Modified 2026-04-29
CVSS v3
CVSS v2
2.6
VIR risk
2.6

Description

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://issues.apache.org/bugzilla/show_bug.cgi?id=52256

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://svn.apache.org/viewvc?view=revision&revision=1227292

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://httpd.apache.org/security/vulnerabilities_22.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-0021

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.2.22-1
debian debianbullseyefixed2.2.22-1
debian debianforkyfixed2.2.22-1
debian debiansidfixed2.2.22-1
debian debiantrixiefixed2.2.22-1

Application impact

VendorProductVersionsFixed
apache apachehttp_server2.2.17
apache apachehttp_server2.2.18
apache apachehttp_server2.2.19
apache apachehttp_server2.2.20
apache apachehttp_server2.2.21

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.