debian · CVE-2010-4410

Quick triage

Priority: not yet assigned Published: Updated: Thu, 23 Jul 2026 01:18:52 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2010-4410 not yet assigned priority: Debian including 3 source packages (libcgi-pm-perl, libcgi-simple-perl, perl), 15 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 15.

Description:

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

cvelogic Threat Intelligence