|
|
| |
|
| |
perl-CGI-Simple: HTTP response splitting
| Package(s): | perl-CGI-Simple |
CVE #(s): | CVE-2010-2761
|
| Created: | December 9, 2010 |
Updated: | December 9, 2011 |
| Description: |
From the Mandriva advisory:
The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm
in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME
boundary string in multipart/x-mixed-replace content, which allows
remote attackers to inject arbitrary HTTP headers and conduct HTTP
response splitting attacks via crafted input that contains this value,
a different vulnerability than CVE-2010-3172 (CVE-2010-2761).
|
| Alerts: |
|
( Log in to post comments)
|
|
|