CVE-2010-4411
published 2010-12-06CVE-2010-4411: Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.58%
83.6th percentile
Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists because of an incomplete fix for CVE-2010-2761.
Affected
260 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| andy_armstrong | cgi.pm | <= 3.50 | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-93g6-7v2r-h2r4: CRLF injection vulnerability in chart
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2010-4572 [MEDIUM] CWE-94 GHSA-93g6-7v2r-h2r4: CRLF injection vulnerability in chart
CRLF injection vulnerability in chart.cgi in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the query string, a different vulnerability than CVE-2010-2761 and CVE-2010-4411.
GHSA
GHSA-wj7r-99wr-72wm: Unspecified vulnerability in CGI
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2010-4411 [MEDIUM] GHSA-wj7r-99wr-72wm: Unspecified vulnerability in CGI
Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists because of an incomplete fix for CVE-2010-2761.
OSV
CVE-2010-4411: Unspecified vulnerability in CGI
osv·2010-12-06·CVSS 4.3
CVE-2010-4411 [MEDIUM] CVE-2010-4411: Unspecified vulnerability in CGI
Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists because of an incomplete fix for CVE-2010-2761.
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2011-05-03·CVSS 7.5
CVE-2010-2761 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: An attacker could send crafted input to Perl and bypass intended
restrictions.
It was discovered that the Safe.pm Perl module incorrectly handled
Safe::reval and Safe::rdo access restrictions. An attacker could use this
flaw to bypass intended restrictions and possibly execute arbitrary code.
(CVE-2010-1168, CVE-2010-1447)
It was discovered that the CGI.pm Perl module incorrectly handled certain
MIME boundary strings. An attacker could use this flaw to inject arbitrary
HTTP headers and perform HTTP response splitting and cross-site scripting
attacks. This issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 10.04 LTS and
10.10. (CVE-2010-2761, CVE-2010-4411)
It was discovered that the CGI.pm Perl module incorrectly handled newline
characters. An attacker
Debian
CVE-2010-4411: libcgi-pm-perl - Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to ...
vendor_debian·2010·CVSS 4.3
CVE-2010-4411 [MEDIUM] CVE-2010-4411: libcgi-pm-perl - Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to ...
Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists because of an incomplete fix for CVE-2010-2761.
Scope: local
bookworm: resolved (fixed in 3.51-1)
bullseye: resolved (fixed in 3.51-1)
forky: resolved (fixed in 3.51-1)
sid: resolved (fixed in 3.51-1)
trixie: resolved (fixed in 3.51-1)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://openwall.com/lists/oss-security/2010/12/01/3http://secunia.com/advisories/43033http://secunia.com/advisories/43068http://secunia.com/advisories/43165http://www.bugzilla.org/security/3.2.9/http://www.mandriva.com/security/advisories?name=MDVSA-2011:008http://www.vupen.com/english/advisories/2011/0106http://www.vupen.com/english/advisories/2011/0207http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0271https://bugzilla.mozilla.org/show_bug.cgi?id=591165http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://openwall.com/lists/oss-security/2010/12/01/3http://secunia.com/advisories/43033http://secunia.com/advisories/43068http://secunia.com/advisories/43165http://www.bugzilla.org/security/3.2.9/http://www.mandriva.com/security/advisories?name=MDVSA-2011:008http://www.vupen.com/english/advisories/2011/0106http://www.vupen.com/english/advisories/2011/0207http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0271https://bugzilla.mozilla.org/show_bug.cgi?id=591165
2010-12-06
Published