4.3
CVSSv2

CVE-2010-4411

Published: 06/12/2010 Updated: 12/02/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Unspecified vulnerability in CGI.pm 3.50 and previous versions allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists because of an incomplete fix for CVE-2010-2761.

Vulnerable Product Search on Vulmon Subscribe to Product

andy armstrong cgi.pm 2.69

andy armstrong cgi.pm 2.71

andy armstrong cgi.pm 2.77

andy armstrong cgi.pm 2.78

andy armstrong cgi.pm 2.86

andy armstrong cgi.pm 2.85

andy armstrong cgi.pm 2.94

andy armstrong cgi.pm 2.93

andy armstrong cgi.pm 2.95

andy armstrong cgi.pm 2.40

andy armstrong cgi.pm 2.38

andy armstrong cgi.pm 2.48

andy armstrong cgi.pm 2.45

andy armstrong cgi.pm 2.55

andy armstrong cgi.pm 2.54

andy armstrong cgi.pm 2.53

andy armstrong cgi.pm 2.62

andy armstrong cgi.pm 2.61

andy armstrong cgi.pm 1.55

andy armstrong cgi.pm 1.56

andy armstrong cgi.pm 2.17

andy armstrong cgi.pm 2.18

andy armstrong cgi.pm 2.24

andy armstrong cgi.pm 2.27

andy armstrong cgi.pm 2.32

andy armstrong cgi.pm 2.35

andy armstrong cgi.pm 2.96

andy armstrong cgi.pm 3.49

andy armstrong cgi.pm 3.44

andy armstrong cgi.pm 3.43

andy armstrong cgi.pm 3.36

andy armstrong cgi.pm 3.35

andy armstrong cgi.pm 3.05

andy armstrong cgi.pm 3.12

andy armstrong cgi.pm 2.97

andy armstrong cgi.pm 3.04

andy armstrong cgi.pm 3.22

andy armstrong cgi.pm 3.27

andy armstrong cgi.pm 3.19

andy armstrong cgi.pm 3.20

andy armstrong cgi.pm 2.67

andy armstrong cgi.pm 2.68

andy armstrong cgi.pm 2.75

andy armstrong cgi.pm 2.751

andy armstrong cgi.pm 2.82

andy armstrong cgi.pm 2.81

andy armstrong cgi.pm 2.92

andy armstrong cgi.pm 2.91

andy armstrong cgi.pm 2.37

andy armstrong cgi.pm 2.49

andy armstrong cgi.pm 2.44

andy armstrong cgi.pm 2.58

andy armstrong cgi.pm 2.66

andy armstrong cgi.pm 2.65

andy armstrong cgi.pm 1.51

andy armstrong cgi.pm 1.52

andy armstrong cgi.pm 2.01

andy armstrong cgi.pm 2.13

andy armstrong cgi.pm 2.20

andy armstrong cgi.pm 2.23

andy armstrong cgi.pm 2.28

andy armstrong cgi.pm 2.31

andy armstrong cgi.pm 1.4

andy armstrong cgi.pm 1.50

andy armstrong cgi.pm 1.45

andy armstrong cgi.pm 3.40

andy armstrong cgi.pm 3.39

andy armstrong cgi.pm 3.32

andy armstrong cgi.pm 3.31

andy armstrong cgi.pm 3.48

andy armstrong cgi.pm 3.08

andy armstrong cgi.pm 3.09

andy armstrong cgi.pm 3.00

andy armstrong cgi.pm 3.01

andy armstrong cgi.pm 3.23

andy armstrong cgi.pm 3.15

andy armstrong cgi.pm 3.16

andy armstrong cgi.pm

andy armstrong cgi.pm 2.70

andy armstrong cgi.pm 2.752

andy armstrong cgi.pm 2.76

andy armstrong cgi.pm 2.84

andy armstrong cgi.pm 2.83

andy armstrong cgi.pm 2.41

andy armstrong cgi.pm 2.42

andy armstrong cgi.pm 2.50

andy armstrong cgi.pm 2.47

andy armstrong cgi.pm 2.57

andy armstrong cgi.pm 2.56

andy armstrong cgi.pm 2.64

andy armstrong cgi.pm 2.63

andy armstrong cgi.pm 1.53

andy armstrong cgi.pm 1.54

andy armstrong cgi.pm 2.14

andy armstrong cgi.pm 2.15

andy armstrong cgi.pm 2.16

andy armstrong cgi.pm 2.22

andy armstrong cgi.pm 2.25

andy armstrong cgi.pm 2.30

andy armstrong cgi.pm 2.33

andy armstrong cgi.pm 1.44

andy armstrong cgi.pm 1.43

andy armstrong cgi.pm 3.42

andy armstrong cgi.pm 3.41

andy armstrong cgi.pm 3.34

andy armstrong cgi.pm 3.33

andy armstrong cgi.pm 3.07

andy armstrong cgi.pm 3.06

andy armstrong cgi.pm 2.99

andy armstrong cgi.pm 2.98

andy armstrong cgi.pm 3.24

andy armstrong cgi.pm 3.21

andy armstrong cgi.pm 3.13

andy armstrong cgi.pm 3.14

andy armstrong cgi.pm 2.72

andy armstrong cgi.pm 2.73

andy armstrong cgi.pm 2.74

andy armstrong cgi.pm 2.79

andy armstrong cgi.pm 2.80

andy armstrong cgi.pm 2.88

andy armstrong cgi.pm 2.87

andy armstrong cgi.pm 2.90

andy armstrong cgi.pm 2.89

andy armstrong cgi.pm 2.39

andy armstrong cgi.pm 2.36

andy armstrong cgi.pm 2.46

andy armstrong cgi.pm 2.43

andy armstrong cgi.pm 2.52

andy armstrong cgi.pm 2.51

andy armstrong cgi.pm 2.60

andy armstrong cgi.pm 2.59

andy armstrong cgi.pm 1.57

andy armstrong cgi.pm 2.0

andy armstrong cgi.pm 2.19

andy armstrong cgi.pm 2.21

andy armstrong cgi.pm 2.26

andy armstrong cgi.pm 2.29

andy armstrong cgi.pm 2.34

andy armstrong cgi.pm 1.42

andy armstrong cgi.pm 3.38

andy armstrong cgi.pm 3.37

andy armstrong cgi.pm 3.30

andy armstrong cgi.pm 3.29

andy armstrong cgi.pm 3.45

andy armstrong cgi.pm 3.46

andy armstrong cgi.pm 3.47

andy armstrong cgi.pm 3.11

andy armstrong cgi.pm 3.10

andy armstrong cgi.pm 3.03

andy armstrong cgi.pm 3.02

andy armstrong cgi.pm 3.28

andy armstrong cgi.pm 3.25

andy armstrong cgi.pm 3.26

andy armstrong cgi.pm 3.17

andy armstrong cgi.pm 3.18

Vendor Advisories

An attacker could send crafted input to Perl and bypass intended restrictions ...
Debian Bug report logs - #644169 libapache2-mod-perl2: PerlOptions -Sections not permitted in server config, but should be Package: libapache2-mod-perl2; Maintainer for libapache2-mod-perl2 is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libapache2-mod-perl2 is src:libapache2-mod-perl2 (PTS, buildd, p ...
Debian Bug report logs - #606370 CVE-2010-2761 CVE-2010-4410 CVE-2010-4411 Package: libcgi-pm-perl; Maintainer for libcgi-pm-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libcgi-pm-perl is src:libcgi-pm-perl (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> ...