CVE Database
/

CVE-2012-5526

Back to search

CVE-2012-5526

Published: Nov 21, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.

VendorProductVersions

n/a

n/a

affected
n/a

References

perl-cgipm-header-injection(80098)
vdb-entry
x_refsource_XF
55314
third-party-advisory
x_refsource_SECUNIA
56562
vdb-entry
x_refsource_BID
USN-1643-1
vendor-advisory
x_refsource_UBUNTU
1027780
vdb-entry
x_refsource_SECTRACK
DSA-2586
vendor-advisory
x_refsource_DEBIAN
RHSA-2013:0685
vendor-advisory
x_refsource_REDHAT
51457
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now