5
CVSSv2

CVE-2012-5572

Published: 30/05/2014 Updated: 24/06/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer prior to 1.3114 allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526.

Vulnerable Product Search on Vulmon Subscribe to Product

dancer dancer

dancer dancer 1.3111_01

dancer dancer 1.3071

dancer dancer 1.150

dancer dancer 1.3111

dancer dancer 1.3110

dancer dancer 1.3079_5

dancer dancer 1.3079_3

dancer dancer 1.3112

dancer dancer 1.3060

Vendor Advisories

Debian Bug report logs - #694279 libdancer-perl: CVE-2012-5572: Cookie name CRLF injection Package: libdancer-perl; Maintainer for libdancer-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libdancer-perl is src:libdancer-perl (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <car ...