ソフト名:CGI.pm, CGI::Simple 1.x
回避策:アップデートにて対応
脆弱性:XSS, HTTPレスポンス分割攻撃, HTTPヘッダインジェクション
ソース:http://search.cpan.org/dist/CGI.pm/
http://search.cpan.org/dist/CGI-Simple/lib/CGI/Simple.pm
http://cpansearch.perl.org/src/LDS/CGI.pm-3.50/Changes
https://github.com/AndyA/CGI--Simple/commit/e4942b871a26c1317a175a91ebb7262eea59b380
http://www.openwall.com/lists/oss-security/2010/12/01/2
http://www.openwall.com/lists/oss-security/2010/12/01/3
http://secunia.com/advisories/42443/
http://secunia.com/advisories/42460/
http://secunia.com/advisories/42461/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2761
CVE:CVE-2010-2761
危険性:Low Risk
登録:
コメントの投稿 (Atom)
0 件のコメント:
コメントを投稿