Your submission was sent successfully! Close

CVE-2010-4572

Published: 28 January 2011

CRLF injection vulnerability in chart.cgi in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the query string, a different vulnerability than CVE-2010-2761 and CVE-2010-4411.

Priority

Medium

Status

Package Release Status
bugzilla
Launchpad, Ubuntu, Debian
Upstream
Released (3.2.10, 3.4.10, 3.6.4)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(dropped by debian)
Patches:
Vendor: http://www.debian.org/security/2011/dsa-2322

Notes

AuthorNote
sbeattie
debian's references to CVE-2010-4572 included libcgi-pm-perl,
libcgi-simple-perl, and perl, but CVE-2010-4410 is the relevant one for
those.

References