LWN.net Logo

perl-CGI-Simple: HTTP response splitting

Package(s):perl-CGI-Simple CVE #(s):CVE-2010-2761
Created:December 9, 2010 Updated:December 9, 2011
Description:

From the Mandriva advisory:

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172 (CVE-2010-2761).

Alerts:
Oracle ELSA-2011-1797 2011-12-08
Oracle ELSA-2011-1797 2011-12-08
Scientific Linux SL-perl-20111208 2011-12-08
CentOS CESA-2011:1797 2011-12-09
CentOS CESA-2011:1797 2011-12-09
Red Hat RHSA-2011:1797-01 2011-12-08
Gentoo 201110-03 2011-10-10
Red Hat RHSA-2011:0558-01 2011-05-19
Fedora FEDORA-2011-0640 2011-01-21
Fedora FEDORA-2011-0654 2011-01-21
Fedora FEDORA-2011-0653 2011-01-21
Fedora FEDORA-2011-0631 2011-01-21
SUSE SUSE-SR:2011:002 2011-01-25
SUSE SUSE-SR:2011:001 2011-01-11
openSUSE openSUSE-SU-2011:0020-1 2011-01-10
openSUSE openSUSE-SU-2011:0064-1 2011-01-20
Mandriva MDVSA-2010:252 2010-12-14
Mandriva MDVSA-2010:250 2010-12-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds