LWN.net Logo

mono: CRLF injection

Package(s):mono CVE #(s):CVE-2008-3906
Created:September 30, 2008 Updated:December 7, 2009
Description: From the CVE entry: CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.
Alerts:
Mandriva MDVSA-2009:322 2009-12-07
Ubuntu USN-826-1 2009-08-26
Mandriva MDVSA-2008:210-1 2008-10-11
Mandriva MDVSA-2008:210 2007-10-03
rPath rPSA-2008-0286-1 2008-09-29

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds