---
title: "CVE-2005-3348\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2005-3348?format=md
keywords: index, follow
---

# CVE-2005-3348

Publication date 18 November 2005

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and
earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before
1.0.0.009, allows remote attackers to spoof web content and poison web
caches via CRLF sequences in the charset parameter.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| egroupware | 7.04 feisty | Fixed 1.0.0.009.dfsg-3-4 |
| 6.10 edgy | Fixed 1.0.0.009.dfsg-3-4 |
| 6.06 LTS dapper | Fixed 1.0.0.009.dfsg-3-4 |
| phpgroupware | 7.04 feisty | Fixed 0.9.16.010-1 |
| 6.10 edgy | Fixed 0.9.16.010-1 |
| 6.06 LTS dapper | Fixed 0.9.16.010-1 |
| phpsysinfo | 7.04 feisty | Fixed 2.3-7 |
| 6.10 edgy | Fixed 2.3-7 |
| 6.06 LTS dapper | Fixed 2.3-7 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3348)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2005-3348)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2005-3348)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2005-3348)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2005-3348>
