CVE-2012-5526
published 2012-11-21CVE-2012-5526: CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject…
PriorityP427medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
3.26%
87.1th percentile
CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| andy_armstrong | cgi.pm | <= 3.62 | — |
| dancer | dancer | <= 1.3113 | — |
| dancer | dancer | — | — |
| dancer | dancer | — | — |
| dancer | dancer | — | — |
| dancer | dancer | — | — |
| dancer | dancer | — | — |
| dancer | dancer | — | — |
| dancer | dancer | — | — |
| dancer | dancer | — | — |
| dancer | dancer | — | — |
| debian | libcgi-pm-perl | < libcgi-pm-perl 3.61-2 (bookworm) | libcgi-pm-perl 3.61-2 (bookworm) |
| debian | libdancer-perl | < libdancer-perl 1.3114+dfsg-1 (bookworm) | libdancer-perl 1.3114+dfsg-1 (bookworm) |
| debian | perl | < libcgi-pm-perl 3.61-2 (bookworm) | libcgi-pm-perl 3.61-2 (bookworm) |
| perl | perl | >= 0 < 5.14.2-16 | 5.14.2-16 |
| perl | perl | >= 0 < 5.14.2-16 | 5.14.2-16 |
| perl | perl | >= 0 < 5.14.2-16 | 5.14.2-16 |
| perl | perl | >= 0 < 5.14.2-16 | 5.14.2-16 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_ubuntu5.1MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 5.1
CVE-2011-2939 [MEDIUM] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: Perl programs could be made to crash or run programs if they receive
specially crafted network traffic or other input.
It was discovered that the decode_xs function in the Encode module is
vulnerable to a heap-based buffer overflow via a crafted Unicode string.
An attacker could use this overflow to cause a denial of service.
(CVE-2011-2939)
It was discovered that the 'new' constructor in the Digest module is
vulnerable to an eval injection. An attacker could use this to execute
arbitrary code. (CVE-2011-3597)
It was discovered that Perl's 'x' string repeat operator is vulnerable
to a heap-based buffer overflow. An attacker could use this to execute
arbitrary code. (CVE-2012-5195)
Ryo Anazawa discovered that the CGI.pm module does not properly esca
Red Hat
perl-CGI: Newline injection due to improper CRLF escaping in Set-Cookie and P3P headers
vendor_redhat·2012-11-12·CVSS 5.0
CVE-2012-5526 [MEDIUM] perl-CGI: Newline injection due to improper CRLF escaping in Set-Cookie and P3P headers
perl-CGI: Newline injection due to improper CRLF escaping in Set-Cookie and P3P headers
CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.
Debian
CVE-2012-5526: libcgi-pm-perl - CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-...
vendor_debian·2012·CVSS 5.0
CVE-2012-5526 [MEDIUM] CVE-2012-5526: libcgi-pm-perl - CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-...
CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.
Scope: local
bookworm: resolved (fixed in 3.61-2)
bullseye: resolved (fixed in 3.61-2)
forky: resolved (fixed in 3.61-2)
sid: resolved (fixed in 3.61-2)
trixie: resolved (fixed in 3.61-2)
Debian
CVE-2012-5572: libdancer-perl - CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Danc...
vendor_debian·2012·CVSS 5.0
CVE-2012-5572 [MEDIUM] CVE-2012-5572: libdancer-perl - CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Danc...
CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526.
Scope: local
bookworm: resolved (fixed in 1.3114+dfsg-1)
bullseye: resolved (fixed in 1.3114+dfsg-1)
forky: resolved (fixed in 1.3114+dfsg-1)
sid: resolved (fixed in 1.3114+dfsg-1)
trixie: resolved (fixed in 1.3114+dfsg-1)
GHSA
GHSA-cqwv-qc24-9rvm: CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie
ghsa_unreviewed·2022-05-17·CVSS 5.0
CVE-2012-5572 [MEDIUM] CWE-20 GHSA-cqwv-qc24-9rvm: CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie
CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526.
GHSA
GHSA-9x3m-wmpr-vc58: CGI
ghsa_unreviewed·2022-05-17
CVE-2012-5526 [MEDIUM] GHSA-9x3m-wmpr-vc58: CGI
CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.
OSV
CVE-2012-5572: CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie
osv·2014-05-30·CVSS 5.0
CVE-2012-5572 [MEDIUM] CVE-2012-5572: CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie
CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526.
OSV
CVE-2012-5526: CGI
osv·2012-11-21·CVSS 5.0
CVE-2012-5526 [MEDIUM] CVE-2012-5526: CGI
CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5572 perl-Dancer: Newline injection due to improper CRLF escaping in cookie() and cookies() methods
bugzilla·2012-11-26·CVSS 5.0
CVE-2012-5572 [MEDIUM] CVE-2012-5572 perl-Dancer: Newline injection due to improper CRLF escaping in cookie() and cookies() methods
CVE-2012-5572 perl-Dancer: Newline injection due to improper CRLF escaping in cookie() and cookies() methods
A security flaw was found in the way Dancer.pm, lightweight yet powerful web application framework / Perl language module, performed sanitization of values to be used for cookie() and cookies() methods. A remote attacker could use this flaw to inject arbitrary headers into responses from (Perl) applications, that use Dancer.pm. A different vulnerability than CVE-2012-5526.
References:
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=694279
[2] https://github.com/sukria/Dancer/issues/859
Discussion:
This issue affects the versions of the perl-Dancer package, as shipped with Fedora release of 16 and 17. Please schedule an update (once there is final upstream patch is available
Bugzilla
CVE-2012-5526 perl-CGI: Newline injection due to improper CRLF escaping in Set-Cookie and P3P headers
bugzilla·2012-11-15·CVSS 5.0
CVE-2012-5526 [MEDIUM] CVE-2012-5526 perl-CGI: Newline injection due to improper CRLF escaping in Set-Cookie and P3P headers
CVE-2012-5526 perl-CGI: Newline injection due to improper CRLF escaping in Set-Cookie and P3P headers
A security flaw was found in the way CGI.pm, a Perl module to handle Common Gateway Interface requests and responses, performed sanitization of values to be used for Set-Cookie and P3P headers. If a Perl CGI.pm module based CGI application reused cookies values and accepted untrusted input from web browser(s), a remote attacker could use this flaw to in an unauthorized way alter member items of the cookie or add new items.
References:
[1] http://cpansearch.perl.org/src/MARKSTOS/CGI.pm-3.63/Changes
[2] https://github.com/markstos/CGI.pm/pull/23
[3] https://bugzilla.redhat.com/show_bug.cgi?id=876974
Discussion:
This issue affects the versions of the perl-CGI package, as shipped with Fedo
Bugzilla
CVE-2012-1090 kernel: cifs: dentry refcount leak when opening a FIFO on lookup leads to panic on unmount
bugzilla·2012-02-28·CVSS 5.5
CVE-2012-1090 [MEDIUM] CVE-2012-1090 kernel: cifs: dentry refcount leak when opening a FIFO on lookup leads to panic on unmount
CVE-2012-1090 kernel: cifs: dentry refcount leak when opening a FIFO on lookup leads to panic on unmount
The cifs code will attempt to open files on lookup under certain circumstances. What happens though if we find that the file we opened was actually a FIFO or other special file? Currently, the open filehandle just ends up being leaked leading to a dentry refcount mismatch and oops on umount.
An user with access to samba share could use this flaw to crash the systems of users that have access to the same samba share.
Introduced by:
http://git.kernel.org/linus/a6ce4932fbdbcd8f8e8c6df76812014351c32892
Proposed upstream patch:
http://thread.gmane.org/gmane.linux.kernel.cifs/5526
Discussion:
Statement:
This issue did not affect the Linux kernel as shipped with Red Hat Enterprise
Linux
http://cpansearch.perl.org/src/MARKSTOS/CGI.pm-3.63/Changeshttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://rhn.redhat.com/errata/RHSA-2013-0685.htmlhttp://secunia.com/advisories/51457http://secunia.com/advisories/55314http://www.debian.org/security/2012/dsa-2586http://www.openwall.com/lists/oss-security/2012/11/15/6http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/56562http://www.securitytracker.com/id?1027780http://www.ubuntu.com/usn/USN-1643-1https://exchange.xforce.ibmcloud.com/vulnerabilities/80098https://github.com/markstos/CGI.pm/pull/23http://cpansearch.perl.org/src/MARKSTOS/CGI.pm-3.63/Changeshttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://rhn.redhat.com/errata/RHSA-2013-0685.htmlhttp://secunia.com/advisories/51457http://secunia.com/advisories/55314http://www.debian.org/security/2012/dsa-2586http://www.openwall.com/lists/oss-security/2012/11/15/6http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/56562http://www.securitytracker.com/id?1027780http://www.ubuntu.com/usn/USN-1643-1https://exchange.xforce.ibmcloud.com/vulnerabilities/80098https://github.com/markstos/CGI.pm/pull/23
2012-11-21
Published