CVE-2012-5572

CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
VendorProductVersion
dancerdancer
𝑥
≤ 1.3113
dancerdancer
1.150
dancerdancer
1.3060
dancerdancer
1.3071
dancerdancer
1.3079_3:_3
dancerdancer
1.3079_5:_5
dancerdancer
1.3110
dancerdancer
1.3111
dancerdancer
1.3111_01:_01
dancerdancer
1.3112
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libdancer-perl
bullseye
1.3513+dfsg-1
fixed
wheezy
no-dsa
bookworm
1.3521+dfsg-1
fixed
sid
1.3521+dfsg-1
fixed
trixie
1.3521+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libdancer-perl
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
oneiric
ignored
lucid
dne
hardy
dne