| Name | CVE-2010-4411 |
| Description | Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists because of an incomplete fix for CVE-2010-2761. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 606370, 606379, 606995 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| libcgi-pm-perl (PTS) | bullseye | 4.51-1 | fixed |
| bookworm | 4.55-1 | fixed | |
| trixie | 4.68-1 | fixed | |
| forky, sid | 4.71-1 | fixed | |
| libcgi-simple-perl (PTS) | bullseye | 1.115-2 | fixed |
| bookworm | 1.280-2+deb12u1 | fixed | |
| trixie | 1.282-1~deb13u1 | fixed | |
| forky, sid | 1.282-1 | fixed | |
| perl (PTS) | bullseye | 5.32.1-4+deb11u3 | fixed |
| bullseye (security) | 5.32.1-4+deb11u4 | fixed | |
| bookworm | 5.36.0-7+deb12u3 | fixed | |
| bookworm (security) | 5.36.0-7+deb12u2 | fixed | |
| forky, sid, trixie | 5.40.1-6 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| libcgi-pm-perl | source | lenny | 3.38-2lenny2 | |||
| libcgi-pm-perl | source | squeeze | 3.49-1squeeze1 | |||
| libcgi-pm-perl | source | (unstable) | 3.51-1 | 606370 | ||
| libcgi-simple-perl | source | lenny | 1.105-1lenny1 | |||
| libcgi-simple-perl | source | (unstable) | 1.111-2 | 606379 | ||
| perl | source | lenny | 5.10.0-19lenny3 | |||
| perl | source | (unstable) | 5.10.1-17 | 606995 |