CVE-2010-4410

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
andy_armstrongcgi.pm
𝑥
≤ 3.49
andy_armstrongcgi.pm
1.4
andy_armstrongcgi.pm
1.42
andy_armstrongcgi.pm
1.43
andy_armstrongcgi.pm
1.44
andy_armstrongcgi.pm
1.45
andy_armstrongcgi.pm
1.50
andy_armstrongcgi.pm
1.51
andy_armstrongcgi.pm
1.52
andy_armstrongcgi.pm
1.53
andy_armstrongcgi.pm
1.54
andy_armstrongcgi.pm
1.55
andy_armstrongcgi.pm
1.56
andy_armstrongcgi.pm
1.57
andy_armstrongcgi.pm
2.0
andy_armstrongcgi.pm
2.01
andy_armstrongcgi.pm
2.13
andy_armstrongcgi.pm
2.14
andy_armstrongcgi.pm
2.15
andy_armstrongcgi.pm
2.16
andy_armstrongcgi.pm
2.17
andy_armstrongcgi.pm
2.18
andy_armstrongcgi.pm
2.19
andy_armstrongcgi.pm
2.20
andy_armstrongcgi.pm
2.21
andy_armstrongcgi.pm
2.22
andy_armstrongcgi.pm
2.23
andy_armstrongcgi.pm
2.24
andy_armstrongcgi.pm
2.25
andy_armstrongcgi.pm
2.26
andy_armstrongcgi.pm
2.27
andy_armstrongcgi.pm
2.28
andy_armstrongcgi.pm
2.29
andy_armstrongcgi.pm
2.30
andy_armstrongcgi.pm
2.31
andy_armstrongcgi.pm
2.32
andy_armstrongcgi.pm
2.33
andy_armstrongcgi.pm
2.34
andy_armstrongcgi.pm
2.35
andy_armstrongcgi.pm
2.36
andy_armstrongcgi.pm
2.37
andy_armstrongcgi.pm
2.38
andy_armstrongcgi.pm
2.39
andy_armstrongcgi.pm
2.40
andy_armstrongcgi.pm
2.41
andy_armstrongcgi.pm
2.42
andy_armstrongcgi.pm
2.43
andy_armstrongcgi.pm
2.44
andy_armstrongcgi.pm
2.45
andy_armstrongcgi.pm
2.46
andy_armstrongcgi.pm
2.47
andy_armstrongcgi.pm
2.48
andy_armstrongcgi.pm
2.49
andy_armstrongcgi.pm
2.50
andy_armstrongcgi.pm
2.51
andy_armstrongcgi.pm
2.52
andy_armstrongcgi.pm
2.53
andy_armstrongcgi.pm
2.54
andy_armstrongcgi.pm
2.55
andy_armstrongcgi.pm
2.56
andy_armstrongcgi.pm
2.57
andy_armstrongcgi.pm
2.58
andy_armstrongcgi.pm
2.59
andy_armstrongcgi.pm
2.60
andy_armstrongcgi.pm
2.61
andy_armstrongcgi.pm
2.62
andy_armstrongcgi.pm
2.63
andy_armstrongcgi.pm
2.64
andy_armstrongcgi.pm
2.65
andy_armstrongcgi.pm
2.66
andy_armstrongcgi.pm
2.67
andy_armstrongcgi.pm
2.68
andy_armstrongcgi.pm
2.69
andy_armstrongcgi.pm
2.70
andy_armstrongcgi.pm
2.71
andy_armstrongcgi.pm
2.72
andy_armstrongcgi.pm
2.73
andy_armstrongcgi.pm
2.74
andy_armstrongcgi.pm
2.75
andy_armstrongcgi.pm
2.76
andy_armstrongcgi.pm
2.77
andy_armstrongcgi.pm
2.78
andy_armstrongcgi.pm
2.79
andy_armstrongcgi.pm
2.80
andy_armstrongcgi.pm
2.81
andy_armstrongcgi.pm
2.82
andy_armstrongcgi.pm
2.83
andy_armstrongcgi.pm
2.84
andy_armstrongcgi.pm
2.85
andy_armstrongcgi.pm
2.86
andy_armstrongcgi.pm
2.87
andy_armstrongcgi.pm
2.88
andy_armstrongcgi.pm
2.89
andy_armstrongcgi.pm
2.90
andy_armstrongcgi.pm
2.91
andy_armstrongcgi.pm
2.92
andy_armstrongcgi.pm
2.93
andy_armstrongcgi.pm
2.94
andy_armstrongcgi.pm
2.95
andy_armstrongcgi.pm
2.96
andy_armstrongcgi.pm
2.97
andy_armstrongcgi.pm
2.98
andy_armstrongcgi.pm
2.99
andy_armstrongcgi.pm
2.751
andy_armstrongcgi.pm
2.752
andy_armstrongcgi.pm
3.00
andy_armstrongcgi.pm
3.01
andy_armstrongcgi.pm
3.02
andy_armstrongcgi.pm
3.03
andy_armstrongcgi.pm
3.04
andy_armstrongcgi.pm
3.05
andy_armstrongcgi.pm
3.06
andy_armstrongcgi.pm
3.07
andy_armstrongcgi.pm
3.08
andy_armstrongcgi.pm
3.09
andy_armstrongcgi.pm
3.10
andy_armstrongcgi.pm
3.11
andy_armstrongcgi.pm
3.12
andy_armstrongcgi.pm
3.13
andy_armstrongcgi.pm
3.14
andy_armstrongcgi.pm
3.15
andy_armstrongcgi.pm
3.16
andy_armstrongcgi.pm
3.17
andy_armstrongcgi.pm
3.18
andy_armstrongcgi.pm
3.19
andy_armstrongcgi.pm
3.20
andy_armstrongcgi.pm
3.21
andy_armstrongcgi.pm
3.22
andy_armstrongcgi.pm
3.23
andy_armstrongcgi.pm
3.24
andy_armstrongcgi.pm
3.25
andy_armstrongcgi.pm
3.26
andy_armstrongcgi.pm
3.27
andy_armstrongcgi.pm
3.28
andy_armstrongcgi.pm
3.29
andy_armstrongcgi.pm
3.30
andy_armstrongcgi.pm
3.31
andy_armstrongcgi.pm
3.32
andy_armstrongcgi.pm
3.33
andy_armstrongcgi.pm
3.34
andy_armstrongcgi.pm
3.35
andy_armstrongcgi.pm
3.36
andy_armstrongcgi.pm
3.37
andy_armstrongcgi.pm
3.38
andy_armstrongcgi.pm
3.39
andy_armstrongcgi.pm
3.40
andy_armstrongcgi.pm
3.41
andy_armstrongcgi.pm
3.42
andy_armstrongcgi.pm
3.43
andy_armstrongcgi.pm
3.44
andy_armstrongcgi.pm
3.45
andy_armstrongcgi.pm
3.46
andy_armstrongcgi.pm
3.47
andy_armstrongcgi.pm
3.48
andy_armstrongcgi-simple
𝑥
≤ 1.112
andy_armstrongcgi-simple
0.078
andy_armstrongcgi-simple
0.079
andy_armstrongcgi-simple
0.080
andy_armstrongcgi-simple
0.081
andy_armstrongcgi-simple
0.082
andy_armstrongcgi-simple
0.83
andy_armstrongcgi-simple
1.0
andy_armstrongcgi-simple
1.1
andy_armstrongcgi-simple
1.1.1
andy_armstrongcgi-simple
1.1.2
andy_armstrongcgi-simple
1.103
andy_armstrongcgi-simple
1.104
andy_armstrongcgi-simple
1.105
andy_armstrongcgi-simple
1.106
andy_armstrongcgi-simple
1.107
andy_armstrongcgi-simple
1.108
andy_armstrongcgi-simple
1.109
andy_armstrongcgi-simple
1.110
andy_armstrongcgi-simple
1.111
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libcgi-pm-perl
bullseye
4.51-1
fixed
bookworm
4.55-1
fixed
sid
4.66-1
fixed
trixie
4.66-1
fixed
libcgi-simple-perl
bullseye
1.115-2
fixed
bookworm
1.280-2
fixed
sid
1.281-1
fixed
trixie
1.281-1
fixed
perl
bullseye
5.32.1-4+deb11u3
fixed
bullseye (security)
5.32.1-4+deb11u4
fixed
bookworm
5.36.0-7+deb12u1
fixed
sid
5.40.0-6
fixed
trixie
5.40.0-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libcgi-pm-perl
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
ignored
lucid
ignored
karmic
ignored
hardy
dne
dapper
dne
libcgi-simple-perl
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
ignored
lucid
ignored
karmic
ignored
hardy
ignored
dapper
ignored
perl
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
Fixed 5.10.1-12ubuntu2.1
released
lucid
Fixed 5.10.1-8ubuntu2.1
released
karmic
ignored
hardy
Fixed 5.8.8-12ubuntu0.5
released
dapper
Fixed 5.8.7-10ubuntu1.3
released
References