Back

MEDIUM

perl-CGI: Newline injection due to improper CRLF escaping in Set-Cookie and P3P headers

Published Nov 21, 2012

Description

CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 21, 2012
Updated Aug 6, 2024
Reserved Oct 24, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Nov 12, 2012