LWN.net Logo

perl-CGI-Simple: HTTP response splitting

Package(s):perl-CGI-Simple CVE #(s):CVE-2010-4410
Created:January 28, 2011 Updated:December 9, 2011
Description:

From the CVE entry:

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

Alerts:
Oracle ELSA-2011-1797 2011-12-08
Oracle ELSA-2011-1797 2011-12-08
Scientific Linux SL-perl-20111208 2011-12-08
CentOS CESA-2011:1797 2011-12-09
CentOS CESA-2011:1797 2011-12-09
Red Hat RHSA-2011:1797-01 2011-12-08
SUSE SUSE-SR:2011:005 2011-04-01
SUSE SUSE-SR:2011:003 2011-02-08
Red Hat RHSA-2011:0558-01 2011-05-19
Ubuntu USN-1129-1 2011-05-03
Fedora FEDORA-2011-0654 2011-01-21
Fedora FEDORA-2011-0653 2011-01-21
Fedora FEDORA-2011-0631 2011-01-21
openSUSE openSUSE-SU-2011:0083-1 2011-01-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds