#VU41270 Input validation error in Zope - CVE-2012-5486


| Updated: 2025-06-08

Vulnerability identifier: #VU41270

Vulnerability risk: Medium

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2012-5486

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Zope
Web applications / Other software

Vendor: Zope

Description

The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.

ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Zope: 2.13.0, 2.13.1, 2.13.2, 2.13.3, 2.13.4, 2.13.5, 2.13.6, 2.13.7, 2.13.8, 2.13.9, 2.13.10, 2.13.11, 2.13.12, 2.13.13, 2.13.14, 2.13.15, 2.13.16, 2.13.17, 2.13.18


External links
https://rhn.redhat.com/errata/RHSA-2014-1194.html
https://www.openwall.com/lists/oss-security/2012/11/10/1
https://bugs.launchpad.net/zope2/+bug/930812
https://plone.org/products/plone/security/advisories/20121106/02
https://plone.org/products/plone-hotfix/releases/20121106


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability