PT-2010-4275 · Cgi.Pm+2 · Cgi.Pm+2
Published
2010-12-06
·
Updated
2024-06-15
·
CVE-2010-2761
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
CGI.pm versions prior to 3.50
CGI::Simple versions prior to 1.112
Description
The issue allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input. This is due to the hardcoded value of the MIME boundary string in multipart/x-mixed-replace content used by the multipart init function.
Recommendations
For CGI.pm versions prior to 3.50, update to version 3.50 or later to resolve the issue.
For CGI::Simple versions prior to 1.112, update to version 1.112 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the multipart init function in CGI.pm and Simple.pm until a patch is available.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cgi.Pm
Cgi-Simple
Red Hat