perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
Published Dec 6, 2010
4.3
MEDIUMCVSS 2.0
EPSS 2.71%
Description
The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.
Affected products
No data.
- ≤ 3.49
- 1.4
- 1.42
- 1.43
- 1.44
- 1.45
- 1.50
- 1.51
- 1.52
- 1.53
- 1.54
- 1.55
- 1.56
- 1.57
- 2.0
- 2.01
- 2.13
- 2.14
- 2.15
- 2.16
- 2.17
- 2.18
- 2.19
- 2.20
- 2.21
- 2.22
- 2.23
- 2.24
- 2.25
- 2.26
- 2.27
- 2.28
- 2.29
- 2.30
- 2.31
- 2.32
- 2.33
- 2.34
- 2.35
- 2.36
- 2.37
- 2.38
- 2.39
- 2.40
- 2.41
- 2.42
- 2.43
- 2.44
- 2.45
- 2.46
- 2.47
- 2.48
- 2.49
- 2.50
- 2.51
- 2.52
- 2.53
- 2.54
- 2.55
- 2.56
- 2.57
- 2.58
- 2.59
- 2.60
- 2.61
- 2.62
- 2.63
- 2.64
- 2.65
- 2.66
- 2.67
- 2.68
- 2.69
- 2.70
- 2.71
- 2.72
- 2.73
- 2.74
- 2.75
- 2.76
- 2.77
- 2.78
- 2.79
- 2.80
- 2.81
- 2.82
- 2.83
- 2.84
- 2.85
- 2.86
- 2.87
- 2.88
- 2.89
- 2.90
- 2.91
- 2.92
- 2.93
- 2.94
- 2.95
- 2.96
- 2.97
- 2.98
- 2.99
- 2.751
- 2.752
- 3.00
- 3.01
- 3.02
- 3.03
- 3.04
- 3.05
- 3.06
- 3.07
- 3.08
- 3.09
- 3.10
- 3.11
- 3.12
- 3.13
- 3.14
- 3.15
- 3.16
- 3.17
- 3.18
- 3.19
- 3.20
- 3.21
- 3.22
- 3.23
- 3.24
- 3.25
- 3.26
- 3.27
- 3.28
- 3.29
- 3.30
- 3.31
- 3.32
- 3.33
- 3.34
- 3.35
- 3.36
- 3.37
- 3.38
- 3.39
- 3.40
- 3.41
- 3.42
- 3.43
- 3.44
- 3.45
- 3.46
- 3.47
- 3.48
- ≤ 1.112
- 0.078
- 0.079
- 0.080
- 0.081
- 0.082
- 0.83
- 1.0
- 1.1
- 1.1.1
- 1.1.2
- 1.103
- 1.104
- 1.105
- 1.106
- 1.107
- 1.108
- 1.109
- 1.110
- 1.111
No data.
Red Hat Enterprise Linux 4
perl-3:5.8.5-57.el4
Fixed · RHSA-2011:1797
Red Hat Enterprise Linux 5
perl-4:5.8.8-32.el5_7.6
Fixed · RHSA-2011:1797
Red Hat Enterprise Linux 6
perl-4:5.10.1-119.el6
Fixed · RHSA-2011:0558
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | perl-3:5.8.5-57.el4 | Fixed | RHSA-2011:1797 |
| Red Hat Enterprise Linux 5 | perl-4:5.8.8-32.el5_7.6 | Fixed | RHSA-2011:1797 |
| Red Hat Enterprise Linux 6 | perl-4:5.10.1-119.el6 | Fixed | RHSA-2011:0558 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 2.71% (0.02713) | 85.49th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.71% (0.02713) | 84.01th | v5 (v2026.06.15) |
| Mar 30, 2025 | 2.72% (0.02718) | 84.64th | v4 (v2025.03.14) |
| Mar 29, 2025 | 6.72% (0.06719) | 85.04th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.72% (0.02718) | 84.95th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.80% (0.00803) | 82.39th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.80% (0.00803) | 81.12th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.80% (0.00803) | 79.02th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (39)
- http://cpansearch.perl.org/src/LDS/CGI.pm-3.50/Changes x_refsource_CONFIRM
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 x_refsource_CONFIRM
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735 x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053576.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053591.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html vendor-advisoryx_refsource_SUSE
- http://openwall.com/lists/oss-security/2010/12/01/1 mailing-listx_refsource_MLISTPatch
- http://openwall.com/lists/oss-security/2010/12/01/2 mailing-listx_refsource_MLIST
- http://openwall.com/lists/oss-security/2010/12/01/3 mailing-listx_refsource_MLISTPatch
- http://osvdb.org/69588 vdb-entryx_refsource_OSVDB
- http://osvdb.org/69589 vdb-entryx_refsource_OSVDB
- http://perl5.git.perl.org/perl.git/blobdiff/a0b94c2432b1d8c20653453a0f6970cb10f59aec..84601d63a7e34958da47dad1e61e27cb3bd467d1:/cpan/CGI/lib/CGI.pm x_refsource_CONFIRMPatch
- http://perl5.git.perl.org/perl.git/commit/84601d63a7e34958da47dad1e61e27cb3bd467d1 x_refsource_CONFIRMPatch
- http://secunia.com/advisories/42877 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43033 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43068 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43147 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43165 third-party-advisoryx_refsource_SECUNIA
- http://www.bugzilla.org/security/3.2.9/ x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:237 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:250 vendor-advisoryx_refsource_MANDRIVA
- http://www.nntp.perl.org/group/perl.perl5.changes/2010/11/msg28043.html x_refsource_CONFIRMPatch
- http://www.redhat.com/support/errata/RHSA-2011-1797.html vendor-advisoryx_refsource_REDHAT
- http://www.vupen.com/english/advisories/2011/0076 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0207 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0212 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0249 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0271 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-2761 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=591165 x_refsource_CONFIRM
- https://bugzilla.mozilla.org/show_bug.cgi?id=600464 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=658976 Issue Tracking
- https://github.com/AndyA/CGI--Simple/commit/e4942b871a26c1317a175a91ebb7262eea59b380 x_refsource_CONFIRMPatch
- https://nvd.nist.gov/vuln/detail/CVE-2010-2761
- https://www.cve.org/CVERecord?id=CVE-2010-2761
Change history (0)
No recorded changes yet.