« Volver al listado

CVE-2012-5526

Estado: ModificadaMedia (5)—

CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-5526",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-11-21T23:55:02.367",
  "references": [
    {
      "url": "http://cpansearch.perl.org/src/MARKSTOS/CGI.pm-3.63/Changes",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-0685.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/51457",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/55314",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.debian.org/security/2012/dsa-2586",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/11/15/6",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/56562",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securitytracker.com/id?1027780",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1643-1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/80098",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/markstos/CGI.pm/pull/23",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://cpansearch.perl.org/src/MARKSTOS/CGI.pm-3.63/Changes",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-0685.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/51457",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/55314",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2012/dsa-2586",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/11/15/6",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/56562",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1027780",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1643-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/80098",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/markstos/CGI.pm/pull/23",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-16"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm."
    },
    {
      "lang": "es",
      "value": "El módulo CGI.pm antes de v3.63 para Perl no escapa correctamente saltos de línea en cabeceras (1) Set-Cookie o (2) P3P, lo que podría permitir a atacantes remotos inyectar cabeceras arbitrarias a las respuestas de las aplicaciones que utilizan CGI.pm."
    }
  ],
  "lastModified": "2026-06-16T23:46:56.927",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:andy_armstrong:cgi.pm:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7292122B-82D7-4EBA-AFE7-3589E9D219FC",
              "versionEndIncluding": "3.62"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}