Back

MEDIUM

perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting

Published Dec 6, 2010

Description

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (29)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Dec 6, 2010
Updated Aug 7, 2024
Reserved Dec 6, 2010

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 16, 2026

Red Hat

Severity Moderate
Public date Nov 10, 2010
Bugzilla 658976

ENISA EUVD

Assigner mitre
Published Dec 6, 2010
Updated Aug 7, 2024

GitHub

No data