DSA-2587-1 libcgi-pm-perl -- HTTP header injection

Related Vulnerabilities: CVE-2012-5526  

It was discovered that the CGI module for Perl does not filter LF characters in the Set-Cookie and P3P headers, potentially allowing attackers to inject HTTP headers. For the stable distribution (squeeze), this problem has been fixed in version 3.49-1squeeze2. For the unstable distribution (sid), this problem has been fixed in version 3.61-2. We recommend that you upgrade your libcgi-pm-perl packages.

Debian Security Advisory

DSA-2587-1 libcgi-pm-perl -- HTTP header injection

Date Reported:
11 Dec 2012
Affected Packages:
libcgi-pm-perl
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 693421.
In Mitre's CVE dictionary: CVE-2012-5526.
More information:

It was discovered that the CGI module for Perl does not filter LF characters in the Set-Cookie and P3P headers, potentially allowing attackers to inject HTTP headers.

For the stable distribution (squeeze), this problem has been fixed in version 3.49-1squeeze2.

For the unstable distribution (sid), this problem has been fixed in version 3.61-2.

We recommend that you upgrade your libcgi-pm-perl packages.