Debian Security Advisory
DSA-2587-1 libcgi-pm-perl -- HTTP header injection
- Date Reported:
- 11 Dec 2012
- Affected Packages:
- libcgi-pm-perl
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 693421.
In Mitre's CVE dictionary: CVE-2012-5526. - More information:
-
It was discovered that the CGI module for Perl does not filter LF characters in the Set-Cookie and P3P headers, potentially allowing attackers to inject HTTP headers.
For the stable distribution (squeeze), this problem has been fixed in version 3.49-1squeeze2.
For the unstable distribution (sid), this problem has been fixed in version 3.61-2.
We recommend that you upgrade your libcgi-pm-perl packages.