Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-2761

Опубликовано: 06 дек. 2010
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

3.50-1
hardy

DNE

karmic

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

not-affected

3.50-1
oneiric

not-affected

3.50-1
precise

not-affected

3.50-1
quantal

not-affected

3.50-1

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

1.111-2
hardy

ignored

end of life
karmic

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

not-affected

1.111-2
oneiric

not-affected

1.111-2
precise

not-affected

1.111-2
quantal

not-affected

1.111-2

Показывать по

РелизСтатусПримечание
dapper

released

5.8.7-10ubuntu1.3
devel

not-affected

5.10.1-17ubuntu1
hardy

released

5.8.8-12ubuntu0.5
karmic

ignored

end of life
lucid

released

5.10.1-8ubuntu2.1
maverick

released

5.10.1-12ubuntu2.1
natty

not-affected

5.10.1-17ubuntu1
oneiric

not-affected

5.10.1-17ubuntu1
precise

not-affected

5.10.1-17ubuntu1
quantal

not-affected

5.10.1-17ubuntu1

Показывать по

EPSS

Процентиль: 85%
0.02718
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

nvd
больше 14 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

debian
больше 14 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.p ...

github
около 3 лет назад

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

oracle-oval
больше 13 лет назад

ELSA-2011-1797: perl security update (MODERATE)

EPSS

Процентиль: 85%
0.02718
Низкий

4.3 Medium

CVSS2