CVE-2010-2761

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
andy_armstrongcgi.pm
𝑥
≤ 3.49
andy_armstrongcgi.pm
1.4
andy_armstrongcgi.pm
1.42
andy_armstrongcgi.pm
1.43
andy_armstrongcgi.pm
1.44
andy_armstrongcgi.pm
1.45
andy_armstrongcgi.pm
1.50
andy_armstrongcgi.pm
1.51
andy_armstrongcgi.pm
1.52
andy_armstrongcgi.pm
1.53
andy_armstrongcgi.pm
1.54
andy_armstrongcgi.pm
1.55
andy_armstrongcgi.pm
1.56
andy_armstrongcgi.pm
1.57
andy_armstrongcgi.pm
2.0
andy_armstrongcgi.pm
2.01
andy_armstrongcgi.pm
2.13
andy_armstrongcgi.pm
2.14
andy_armstrongcgi.pm
2.15
andy_armstrongcgi.pm
2.16
andy_armstrongcgi.pm
2.17
andy_armstrongcgi.pm
2.18
andy_armstrongcgi.pm
2.19
andy_armstrongcgi.pm
2.20
andy_armstrongcgi.pm
2.21
andy_armstrongcgi.pm
2.22
andy_armstrongcgi.pm
2.23
andy_armstrongcgi.pm
2.24
andy_armstrongcgi.pm
2.25
andy_armstrongcgi.pm
2.26
andy_armstrongcgi.pm
2.27
andy_armstrongcgi.pm
2.28
andy_armstrongcgi.pm
2.29
andy_armstrongcgi.pm
2.30
andy_armstrongcgi.pm
2.31
andy_armstrongcgi.pm
2.32
andy_armstrongcgi.pm
2.33
andy_armstrongcgi.pm
2.34
andy_armstrongcgi.pm
2.35
andy_armstrongcgi.pm
2.36
andy_armstrongcgi.pm
2.37
andy_armstrongcgi.pm
2.38
andy_armstrongcgi.pm
2.39
andy_armstrongcgi.pm
2.40
andy_armstrongcgi.pm
2.41
andy_armstrongcgi.pm
2.42
andy_armstrongcgi.pm
2.43
andy_armstrongcgi.pm
2.44
andy_armstrongcgi.pm
2.45
andy_armstrongcgi.pm
2.46
andy_armstrongcgi.pm
2.47
andy_armstrongcgi.pm
2.48
andy_armstrongcgi.pm
2.49
andy_armstrongcgi.pm
2.50
andy_armstrongcgi.pm
2.51
andy_armstrongcgi.pm
2.52
andy_armstrongcgi.pm
2.53
andy_armstrongcgi.pm
2.54
andy_armstrongcgi.pm
2.55
andy_armstrongcgi.pm
2.56
andy_armstrongcgi.pm
2.57
andy_armstrongcgi.pm
2.58
andy_armstrongcgi.pm
2.59
andy_armstrongcgi.pm
2.60
andy_armstrongcgi.pm
2.61
andy_armstrongcgi.pm
2.62
andy_armstrongcgi.pm
2.63
andy_armstrongcgi.pm
2.64
andy_armstrongcgi.pm
2.65
andy_armstrongcgi.pm
2.66
andy_armstrongcgi.pm
2.67
andy_armstrongcgi.pm
2.68
andy_armstrongcgi.pm
2.69
andy_armstrongcgi.pm
2.70
andy_armstrongcgi.pm
2.71
andy_armstrongcgi.pm
2.72
andy_armstrongcgi.pm
2.73
andy_armstrongcgi.pm
2.74
andy_armstrongcgi.pm
2.75
andy_armstrongcgi.pm
2.76
andy_armstrongcgi.pm
2.77
andy_armstrongcgi.pm
2.78
andy_armstrongcgi.pm
2.79
andy_armstrongcgi.pm
2.80
andy_armstrongcgi.pm
2.81
andy_armstrongcgi.pm
2.82
andy_armstrongcgi.pm
2.83
andy_armstrongcgi.pm
2.84
andy_armstrongcgi.pm
2.85
andy_armstrongcgi.pm
2.86
andy_armstrongcgi.pm
2.87
andy_armstrongcgi.pm
2.88
andy_armstrongcgi.pm
2.89
andy_armstrongcgi.pm
2.90
andy_armstrongcgi.pm
2.91
andy_armstrongcgi.pm
2.92
andy_armstrongcgi.pm
2.93
andy_armstrongcgi.pm
2.94
andy_armstrongcgi.pm
2.95
andy_armstrongcgi.pm
2.96
andy_armstrongcgi.pm
2.97
andy_armstrongcgi.pm
2.98
andy_armstrongcgi.pm
2.99
andy_armstrongcgi.pm
2.751
andy_armstrongcgi.pm
2.752
andy_armstrongcgi.pm
3.00
andy_armstrongcgi.pm
3.01
andy_armstrongcgi.pm
3.02
andy_armstrongcgi.pm
3.03
andy_armstrongcgi.pm
3.04
andy_armstrongcgi.pm
3.05
andy_armstrongcgi.pm
3.06
andy_armstrongcgi.pm
3.07
andy_armstrongcgi.pm
3.08
andy_armstrongcgi.pm
3.09
andy_armstrongcgi.pm
3.10
andy_armstrongcgi.pm
3.11
andy_armstrongcgi.pm
3.12
andy_armstrongcgi.pm
3.13
andy_armstrongcgi.pm
3.14
andy_armstrongcgi.pm
3.15
andy_armstrongcgi.pm
3.16
andy_armstrongcgi.pm
3.17
andy_armstrongcgi.pm
3.18
andy_armstrongcgi.pm
3.19
andy_armstrongcgi.pm
3.20
andy_armstrongcgi.pm
3.21
andy_armstrongcgi.pm
3.22
andy_armstrongcgi.pm
3.23
andy_armstrongcgi.pm
3.24
andy_armstrongcgi.pm
3.25
andy_armstrongcgi.pm
3.26
andy_armstrongcgi.pm
3.27
andy_armstrongcgi.pm
3.28
andy_armstrongcgi.pm
3.29
andy_armstrongcgi.pm
3.30
andy_armstrongcgi.pm
3.31
andy_armstrongcgi.pm
3.32
andy_armstrongcgi.pm
3.33
andy_armstrongcgi.pm
3.34
andy_armstrongcgi.pm
3.35
andy_armstrongcgi.pm
3.36
andy_armstrongcgi.pm
3.37
andy_armstrongcgi.pm
3.38
andy_armstrongcgi.pm
3.39
andy_armstrongcgi.pm
3.40
andy_armstrongcgi.pm
3.41
andy_armstrongcgi.pm
3.42
andy_armstrongcgi.pm
3.43
andy_armstrongcgi.pm
3.44
andy_armstrongcgi.pm
3.45
andy_armstrongcgi.pm
3.46
andy_armstrongcgi.pm
3.47
andy_armstrongcgi.pm
3.48
andy_armstrongcgi-simple
𝑥
≤ 1.112
andy_armstrongcgi-simple
0.078
andy_armstrongcgi-simple
0.079
andy_armstrongcgi-simple
0.080
andy_armstrongcgi-simple
0.081
andy_armstrongcgi-simple
0.082
andy_armstrongcgi-simple
0.83
andy_armstrongcgi-simple
1.0
andy_armstrongcgi-simple
1.1
andy_armstrongcgi-simple
1.1.1
andy_armstrongcgi-simple
1.1.2
andy_armstrongcgi-simple
1.103
andy_armstrongcgi-simple
1.104
andy_armstrongcgi-simple
1.105
andy_armstrongcgi-simple
1.106
andy_armstrongcgi-simple
1.107
andy_armstrongcgi-simple
1.108
andy_armstrongcgi-simple
1.109
andy_armstrongcgi-simple
1.110
andy_armstrongcgi-simple
1.111
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libcgi-pm-perl
bookworm
4.55-1
fixed
bullseye
4.51-1
fixed
sid
4.66-1
fixed
trixie
4.66-1
fixed
libcgi-simple-perl
bookworm
1.280-2
fixed
bullseye
1.115-2
fixed
sid
1.281-1
fixed
trixie
1.281-1
fixed
perl
bookworm
5.36.0-7+deb12u1
fixed
bullseye
5.32.1-4+deb11u3
fixed
bullseye (security)
5.32.1-4+deb11u4
fixed
sid
5.40.0-6
fixed
trixie
5.40.0-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libcgi-pm-perl
dapper
dne
hardy
dne
karmic
ignored
lucid
ignored
maverick
ignored
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
libcgi-simple-perl
dapper
ignored
hardy
ignored
karmic
ignored
lucid
ignored
maverick
ignored
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
perl
dapper
Fixed 5.8.7-10ubuntu1.3
released
hardy
Fixed 5.8.8-12ubuntu0.5
released
karmic
ignored
lucid
Fixed 5.10.1-8ubuntu2.1
released
maverick
Fixed 5.10.1-12ubuntu2.1
released
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
perl
suse enterprise desktop 15
5.26.1-5.41
fixed
suse enterprise desktop 15 SP1
5.26.1-7.6.1
fixed
suse enterprise sap 12 SP5
5.18.2-12.20.1
fixed
suse enterprise sap 15
5.26.1-5.41
fixed
suse enterprise sap 15 SP1
5.26.1-7.6.1
fixed
suse enterprise server 12
5.18.2-3.7
fixed
suse enterprise server 12 SP1
5.18.2-3.7
fixed
suse enterprise server 12 SP2
5.18.2-11.1
fixed
suse enterprise server 12 SP3
5.18.2-11.1
fixed
suse enterprise server 12 SP5
5.18.2-12.20.1
fixed
suse enterprise server 15
5.26.1-5.41
fixed
suse enterprise server 15 SP1
5.26.1-7.6.1
fixed
perl-32bit
suse enterprise sap 12 SP5
5.18.2-12.20.1
fixed
suse enterprise server 12
5.18.2-3.7
fixed
suse enterprise server 12 SP1
5.18.2-3.7
fixed
suse enterprise server 12 SP2
5.18.2-11.1
fixed
suse enterprise server 12 SP3
5.18.2-11.1
fixed
suse enterprise server 12 SP5
5.18.2-12.20.1
fixed
perl-base
suse enterprise desktop 15
5.26.1-5.41
fixed
suse enterprise desktop 15 SP1
5.26.1-7.6.1
fixed
suse enterprise sap 12 SP5
5.18.2-12.20.1
fixed
suse enterprise sap 15
5.26.1-5.41
fixed
suse enterprise sap 15 SP1
5.26.1-7.6.1
fixed
suse enterprise server 12
5.18.2-3.7
fixed
suse enterprise server 12 SP1
5.18.2-3.7
fixed
suse enterprise server 12 SP2
5.18.2-11.1
fixed
suse enterprise server 12 SP3
5.18.2-11.1
fixed
suse enterprise server 12 SP5
5.18.2-12.20.1
fixed
suse enterprise server 15
5.26.1-5.41
fixed
suse enterprise server 15 SP1
5.26.1-7.6.1
fixed
perl-base-32bit
suse enterprise desktop 15
5.26.1-5.41
fixed
suse enterprise desktop 15 SP1
5.26.1-7.6.1
fixed
suse enterprise sap 15
5.26.1-5.41
fixed
suse enterprise sap 15 SP1
5.26.1-7.6.1
fixed
suse enterprise server 15
5.26.1-5.41
fixed
suse enterprise server 15 SP1
5.26.1-7.6.1
fixed
perl-doc
suse enterprise sap 12 SP5
5.18.2-12.20.1
fixed
suse enterprise server 12
5.18.2-3.7
fixed
suse enterprise server 12 SP1
5.18.2-3.7
fixed
suse enterprise server 12 SP2
5.18.2-11.1
fixed
suse enterprise server 12 SP3
5.18.2-11.1
fixed
suse enterprise server 12 SP5
5.18.2-12.20.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
perl
RHEL 6
4:5.10.1-119.el6
fixed
perl-Archive-Extract
RHEL 6
1:0.38-119.el6
fixed
perl-Archive-Tar
RHEL 6
0:1.58-119.el6
fixed
perl-CGI
RHEL 6
0:3.51-119.el6
fixed
perl-CPAN
RHEL 6
0:1.9402-119.el6
fixed
perl-CPANPLUS
RHEL 6
0:0.88-119.el6
fixed
perl-Compress-Raw-Zlib
RHEL 6
0:2.023-119.el6
fixed
perl-Compress-Zlib
RHEL 6
0:2.020-119.el6
fixed
perl-Digest-SHA
RHEL 6
1:5.47-119.el6
fixed
perl-ExtUtils-CBuilder
RHEL 6
1:0.27-119.el6
fixed
perl-ExtUtils-Embed
RHEL 6
0:1.28-119.el6
fixed
perl-ExtUtils-MakeMaker
RHEL 6
0:6.55-119.el6
fixed
perl-ExtUtils-ParseXS
RHEL 6
1:2.2003.0-119.el6
fixed
perl-File-Fetch
RHEL 6
0:0.26-119.el6
fixed
perl-IO-Compress-Base
RHEL 6
0:2.020-119.el6
fixed
perl-IO-Compress-Zlib
RHEL 6
0:2.020-119.el6
fixed
perl-IO-Zlib
RHEL 6
1:1.09-119.el6
fixed
perl-IPC-Cmd
RHEL 6
1:0.56-119.el6
fixed
perl-Locale-Maketext-Simple
RHEL 6
1:0.18-119.el6
fixed
perl-Log-Message
RHEL 6
1:0.02-119.el6
fixed
perl-Log-Message-Simple
RHEL 6
0:0.04-119.el6
fixed
perl-Module-Build
RHEL 6
1:0.3500-119.el6
fixed
perl-Module-CoreList
RHEL 6
0:2.18-119.el6
fixed
perl-Module-Load
RHEL 6
1:0.16-119.el6
fixed
perl-Module-Load-Conditional
RHEL 6
0:0.30-119.el6
fixed
perl-Module-Loaded
RHEL 6
1:0.02-119.el6
fixed
perl-Module-Pluggable
RHEL 6
1:3.90-119.el6
fixed
perl-Object-Accessor
RHEL 6
1:0.34-119.el6
fixed
perl-Package-Constants
RHEL 6
1:0.02-119.el6
fixed
perl-Params-Check
RHEL 6
1:0.26-119.el6
fixed
perl-Parse-CPAN-Meta
RHEL 6
1:1.40-119.el6
fixed
perl-Pod-Escapes
RHEL 6
1:1.04-119.el6
fixed
perl-Pod-Simple
RHEL 6
1:3.13-119.el6
fixed
perl-Term-UI
RHEL 6
0:0.20-119.el6
fixed
perl-Test-Harness
RHEL 6
0:3.17-119.el6
fixed
perl-Test-Simple
RHEL 6
0:0.92-119.el6
fixed
perl-Time-HiRes
RHEL 6
4:1.9721-119.el6
fixed
perl-Time-Piece
RHEL 6
0:1.15-119.el6
fixed
perl-core
RHEL 6
0:5.10.1-119.el6
fixed
perl-devel
RHEL 6
4:5.10.1-119.el6
fixed
perl-libs
RHEL 6
4:5.10.1-119.el6
fixed
perl-parent
RHEL 6
1:0.221-119.el6
fixed
perl-suidperl
RHEL 6
4:5.10.1-119.el6
fixed
perl-version
RHEL 6
3:0.77-119.el6
fixed
References