CVE-2010-3172
published 2010-11-05CVE-2010-3172: CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web…
PriorityP413low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
1.79%
76.0th percentile
CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL.
Affected
277 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| andy_armstrong | cgi-simple | <= 1.112 | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi.pm | <= 3.49 | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rqgr-h8g8-4p6w: CRLF injection vulnerability in Bugzilla before 3
ghsa_unreviewed·2022-05-17
CVE-2010-3172 [LOW] CWE-94 GHSA-rqgr-h8g8-4p6w: CRLF injection vulnerability in Bugzilla before 3
CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL.
GHSA
GHSA-63qf-cwcv-ff3r: CRLF injection vulnerability in the header function in (1) CGI
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2010-4410 [MEDIUM] CWE-94 GHSA-63qf-cwcv-ff3r: CRLF injection vulnerability in the header function in (1) CGI
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.
GHSA
GHSA-8x6h-gq6j-8x3j: The multipart_init function in (1) CGI
ghsa_unreviewed·2022-05-17·CVSS 2.6
CVE-2010-2761 [LOW] CWE-94 GHSA-8x6h-gq6j-8x3j: The multipart_init function in (1) CGI
The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.
OSV
CVE-2010-2761: The multipart_init function in (1) CGI
osv·2010-12-06·CVSS 4.3
CVE-2010-2761 [MEDIUM] CVE-2010-2761: The multipart_init function in (1) CGI
The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.
OSV
CVE-2010-4410: CRLF injection vulnerability in the header function in (1) CGI
osv·2010-12-06·CVSS 4.3
CVE-2010-4410 [MEDIUM] CVE-2010-4410: CRLF injection vulnerability in the header function in (1) CGI
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.
Red Hat
perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
vendor_redhat·2010-11-10·CVSS 4.3
CVE-2010-4410 [MEDIUM] perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.
Red Hat
perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
vendor_redhat·2010-11-10·CVSS 4.3
CVE-2010-2761 [MEDIUM] perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.
Debian
CVE-2010-4410: libcgi-pm-perl - CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 an...
vendor_debian·2010·CVSS 4.3
CVE-2010-4410 [MEDIUM] CVE-2010-4410: libcgi-pm-perl - CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 an...
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.
Scope: local
bookworm: resolved (fixed in 3.50-1)
bullseye: resolved (fixed in 3.50-1)
forky: resolved (fixed in 3.50-1)
sid: resolved (fixed in 3.50-1)
trixie: resolved (fixed in 3.50-1)
Debian
CVE-2010-2761: libcgi-pm-perl - The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::...
vendor_debian·2010·CVSS 4.3
CVE-2010-2761 [MEDIUM] CVE-2010-2761: libcgi-pm-perl - The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::...
The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.
Scope: local
bookworm: resolved (fixed in 3.50-1)
bullseye: resolved (fixed in 3.50-1)
forky: resolved (fixed in 3.50-1)
sid: resolved (fixed in 3.50-1)
trixie: resolved (fixed in 3.50-1)
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0520 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID SELECT
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID SELECT"; flow:established,to_server; http.uri; content:"/gallery.php?"; nocase; content:"picID="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0520; reference:url,www.milw0rm.com/exploits/3172; classtype:web-application-attack; sid:2005239; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0520 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID UPDATE
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID UPDATE"; flow:established,to_server; http.uri; content:"/gallery.php?"; nocase; content:"picID="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-0520; reference:url,www.milw0rm.com/exploits/3172; classtype:web-application-attack; sid:2005244; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-0520 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID ASCII
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID ASCII"; flow:established,to_server; http.uri; content:"/gallery.php?"; nocase; content:"picID="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0520; reference:url,www.milw0rm.com/exploits/3172; classtype:web-application-attack; sid:2005243; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0520 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID UNION SELECT
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID UNION SELECT"; flow:established,to_server; http.uri; content:"/gallery.php?"; nocase; content:"picID="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0520; reference:url,www.milw0rm.com/exploits/3172; classtype:web-application-attack; sid:2005240; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_t
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0520 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID DELETE
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID DELETE"; flow:established,to_server; http.uri; content:"/gallery.php?"; nocase; content:"picID="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0520; reference:url,www.milw0rm.com/exploits/3172; classtype:web-application-attack; sid:2005242; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0520 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID INSERT
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- gallery.php picID INSERT"; flow:established,to_server; http.uri; content:"/gallery.php?"; nocase; content:"picID="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-0520; reference:url,www.milw0rm.com/exploits/3172; classtype:web-application-attack; sid:2005241; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T
No public exploits indexed.
Bugzilla
perl-CGI-Simple: CRLF injection vulnerability via a crafted URL
bugzilla·2010-12-01·CVSS 2.6
[LOW] perl-CGI-Simple: CRLF injection vulnerability via a crafted URL
perl-CGI-Simple: CRLF injection vulnerability via a crafted URL
Masahiro Yamada reported a CRLF injection vulnerability in perl-CGI-Simple
module, allowing remote attackers to inject arbitrary HTTP headers and
content, and conduct HTTP response splitting attacks, via a crafted URL.
References:
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=600464
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=600464#c13
[3] https://bugzilla.mozilla.org/show_bug.cgi?id=600464#c31
[4] https://github.com/digg/stream/issues#issue/1
[5] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3172
Upstream changeset:
[6] https://github.com/AndyA/CGI--Simple/commit/e4942b871a26c1317a175a91ebb7262eea59b380
Note: New CVE identifier (against [5]) has been requested for the occurrence
of this issue in perl-CGI-S
Bugzilla
perl-CGI, perl-CGI-Simple: CVE-2010-2761 - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
bugzilla·2010-12-01·CVSS 4.3
CVE-2010-2761 [MEDIUM] perl-CGI, perl-CGI-Simple: CVE-2010-2761 - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
perl-CGI, perl-CGI-Simple: CVE-2010-2761 - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
1, perl-CGI package issues description:
Masahiro Yamada reported a CRLF injection vulnerability in perl-CGI
module, allowing remote attackers to inject arbitrary HTTP headers and
content, and conduct HTTP response splitting attacks, via a crafted URL.
References:
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=600464
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=600464#c29
[3] https://github.com/digg/stream/issues#issue/1
[4] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3172
Upstream changeset:
[5] http://www2.rbfh.de/cgi/cgit.cgi/perl5.git/commit/?id=84601d63a7e34958da47dad1e61e27cb3bd467d1
Note: New CVE identifier
Bugzilla
CVE-2010-3172 bugzilla: header and content injection vulnerability via Server Push
bugzilla·2010-11-03·CVSS 2.6
CVE-2010-3172 [LOW] CVE-2010-3172 bugzilla: header and content injection vulnerability via Server Push
CVE-2010-3172 bugzilla: header and content injection vulnerability via Server Push
It was reported that it was possible for a remote attacker to cause Bugzilla to inject both headers and content to any browser that supported "Server Push" (mostly Gecko-based browser such as Firefox) by inserting a certain string into a URL. This could lead to XSS vulnerabilities or possibly other more dangerous security issues as well.
This issue has been assigned the name CVE-2010-3172 and is corrected in upstream stable releases 3.2.9, 3.4.9, and 3.6.3.
References:
http://www.bugzilla.org/security/3.2.8/
https://bugzilla.mozilla.org/show_bug.cgi?id=600464
Discussion:
Created bugzilla tracking bugs for this issue
Affects: fedora-all [bug 649406]
Bugzilla
CVE-2010-3172 CVE-2010-3764 bugzilla various flaws [fedora-all]
bugzilla·2010-11-03·CVSS 2.6
CVE-2010-3172 [LOW] CVE-2010-3172 CVE-2010-3764 bugzilla various flaws [fedora-all]
CVE-2010-3172 CVE-2010-3764 bugzilla various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=649398
Please note: this issue affects multiple supported
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050813.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050820.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050830.htmlhttp://secunia.com/advisories/42271http://www.bugzilla.org/security/3.2.8/http://www.securitytracker.com/id?1024683http://www.vupen.com/english/advisories/2010/2878http://www.vupen.com/english/advisories/2010/2975https://bugzilla.mozilla.org/show_bug.cgi?id=600464http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050813.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050820.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050830.htmlhttp://secunia.com/advisories/42271http://www.bugzilla.org/security/3.2.8/http://www.securitytracker.com/id?1024683http://www.vupen.com/english/advisories/2010/2878http://www.vupen.com/english/advisories/2010/2975https://bugzilla.mozilla.org/show_bug.cgi?id=600464
2010-11-05
Published