LWN.net Logo

perl-CGI: header injection

Package(s):perl-CGI CVE #(s):CVE-2012-5526
Created:November 28, 2012 Updated:December 19, 2012
Description: From the CVE entry:

CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.

Alerts:
Fedora FEDORA-2012-18318 2012-11-28
Mageia MGASA-2012-0346 2012-11-29
Ubuntu USN-1643-1 2012-11-29
Debian DSA-2586-1 2012-12-11
Debian DSA-2587-1 2012-12-11
Mandriva MDVSA-2012:180 2012-12-17
Fedora FEDORA-2012-18330 2012-12-18
Fedora FEDORA-2012-18330 2012-12-18
Fedora FEDORA-2012-19282 2012-12-13
Fedora FEDORA-2012-19282 2012-12-13
SUSE SUSE-SU-2013:0441-1 2013-03-13
SUSE SUSE-SU-2013:0442-1 2013-03-13
openSUSE openSUSE-SU-2013:0497-1 2013-03-20
openSUSE openSUSE-SU-2013:0502-1 2013-03-20
Red Hat RHSA-2013:0685-01 2013-03-26
CentOS CESA-2013:0685 2013-03-26
CentOS CESA-2013:0685 2013-03-26
Oracle ELSA-2013-0685 2013-03-26
Oracle ELSA-2013-0685 2013-03-27
Scientific Linux SL-perl-20130327 2013-03-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds