perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
Published Dec 6, 2010
4.3
MEDIUMCVSS 2.0
EPSS 2.49%
Description
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.
Affected products
No data.
- ≤ 3.49
- 1.4
- 1.42
- 1.43
- 1.44
- 1.45
- 1.50
- 1.51
- 1.52
- 1.53
- 1.54
- 1.55
- 1.56
- 1.57
- 2.0
- 2.01
- 2.13
- 2.14
- 2.15
- 2.16
- 2.17
- 2.18
- 2.19
- 2.20
- 2.21
- 2.22
- 2.23
- 2.24
- 2.25
- 2.26
- 2.27
- 2.28
- 2.29
- 2.30
- 2.31
- 2.32
- 2.33
- 2.34
- 2.35
- 2.36
- 2.37
- 2.38
- 2.39
- 2.40
- 2.41
- 2.42
- 2.43
- 2.44
- 2.45
- 2.46
- 2.47
- 2.48
- 2.49
- 2.50
- 2.51
- 2.52
- 2.53
- 2.54
- 2.55
- 2.56
- 2.57
- 2.58
- 2.59
- 2.60
- 2.61
- 2.62
- 2.63
- 2.64
- 2.65
- 2.66
- 2.67
- 2.68
- 2.69
- 2.70
- 2.71
- 2.72
- 2.73
- 2.74
- 2.75
- 2.76
- 2.77
- 2.78
- 2.79
- 2.80
- 2.81
- 2.82
- 2.83
- 2.84
- 2.85
- 2.86
- 2.87
- 2.88
- 2.89
- 2.90
- 2.91
- 2.92
- 2.93
- 2.94
- 2.95
- 2.96
- 2.97
- 2.98
- 2.99
- 2.751
- 2.752
- 3.00
- 3.01
- 3.02
- 3.03
- 3.04
- 3.05
- 3.06
- 3.07
- 3.08
- 3.09
- 3.10
- 3.11
- 3.12
- 3.13
- 3.14
- 3.15
- 3.16
- 3.17
- 3.18
- 3.19
- 3.20
- 3.21
- 3.22
- 3.23
- 3.24
- 3.25
- 3.26
- 3.27
- 3.28
- 3.29
- 3.30
- 3.31
- 3.32
- 3.33
- 3.34
- 3.35
- 3.36
- 3.37
- 3.38
- 3.39
- 3.40
- 3.41
- 3.42
- 3.43
- 3.44
- 3.45
- 3.46
- 3.47
- 3.48
- ≤ 1.112
- 0.078
- 0.079
- 0.080
- 0.081
- 0.082
- 0.83
- 1.0
- 1.1
- 1.1.1
- 1.1.2
- 1.103
- 1.104
- 1.105
- 1.106
- 1.107
- 1.108
- 1.109
- 1.110
- 1.111
No data.
Red Hat Enterprise Linux 4
perl-3:5.8.5-57.el4
Fixed · RHSA-2011:1797
Red Hat Enterprise Linux 5
perl-4:5.8.8-32.el5_7.6
Fixed · RHSA-2011:1797
Red Hat Enterprise Linux 6
perl-4:5.10.1-119.el6
Fixed · RHSA-2011:0558
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | perl-3:5.8.5-57.el4 | Fixed | RHSA-2011:1797 |
| Red Hat Enterprise Linux 5 | perl-4:5.8.8-32.el5_7.6 | Fixed | RHSA-2011:1797 |
| Red Hat Enterprise Linux 6 | perl-4:5.10.1-119.el6 | Fixed | RHSA-2011:0558 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (29)
- http://cpansearch.perl.org/src/LDS/CGI.pm-3.50/Changes x_refsource_CONFIRM
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 x_refsource_CONFIRM
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735 x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053576.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053591.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html vendor-advisoryx_refsource_SUSE
- http://openwall.com/lists/oss-security/2010/12/01/1 mailing-listx_refsource_MLISTPatch
- http://openwall.com/lists/oss-security/2010/12/01/2 mailing-listx_refsource_MLISTPatch
- http://openwall.com/lists/oss-security/2010/12/01/3 mailing-listx_refsource_MLISTPatch
- http://perl5.git.perl.org/perl.git/blobdiff/a0b94c2432b1d8c20653453a0f6970cb10f59aec..84601d63a7e34958da47dad1e61e27cb3bd467d1:/cpan/CGI/lib/CGI.pm x_refsource_CONFIRMPatch
- http://perl5.git.perl.org/perl.git/commit/84601d63a7e34958da47dad1e61e27cb3bd467d1 x_refsource_CONFIRMPatch
- http://secunia.com/advisories/43068 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43147 third-party-advisoryx_refsource_SECUNIA
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:237 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:252 vendor-advisoryx_refsource_MANDRIVA
- http://www.nntp.perl.org/group/perl.perl5.changes/2010/11/msg28043.html x_refsource_CONFIRMPatch
- http://www.redhat.com/support/errata/RHSA-2011-1797.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/44199 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/45145 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2010/3230 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0212 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0249 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-4410 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=658970 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=658976 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-4379 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-4410
- https://www.cve.org/CVERecord?id=CVE-2010-4410
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data