LWN.net Logo

perl-CGI: HTTP response splitting attacks

Package(s):perl-CGI CVE #(s):CVE-2010-4411
Created:January 17, 2011 Updated:January 31, 2011
Description: From the Mandriva advisory:

Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists because of an incomplete fix for CVE-2010-2761.

Alerts:
Gentoo 201110-03 2011-10-10
Fedora FEDORA-2011-0653 2011-01-21
Fedora FEDORA-2011-0631 2011-01-21
openSUSE openSUSE-SU-2011:0083-1 2011-01-28
openSUSE openSUSE-SU-2011:0064-1 2011-01-20
Mandriva MDVSA-2011:008 2011-01-14
SUSE SUSE-SR:2011:002 2011-01-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds