Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <846296467.37907315.1353953215439.JavaMail.root@redhat.com>
Date: Mon, 26 Nov 2012 13:06:55 -0500 (EST)
From: Jan Lieskovsky <jlieskov@...hat.com>
To: oss-security@...ts.openwall.com
Cc: "Steven M. Christey" <coley@...us.mitre.org>, Sawyer X <xsawyerx@...n.org>,
        Petr Pisar <ppisar@...hat.com>
Subject: CVE Request -- Dancer.pm / perl-Dancer / libdancer-perl: Newline
 injection due to improper CRLF escaping in cookie() and cookies() methods
 (different vulnerability than CVE-2012-5526)

Hello Kurt, Steve, vendors,

  a security flaw was found in the way Dancer.pm,
lightweight yet powerful web application framework
/ Perl language module, performed sanitization of
values to be used for cookie() and cookies() methods.
A remote attacker could use this flaw to inject arbitrary
headers into responses from (Perl) applications, that use
Dancer.pm. A different vulnerability than CVE-2012-5526.

References:
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=694279
[2] https://github.com/sukria/Dancer/issues/859
[3] https://bugzilla.redhat.com/show_bug.cgi?id=880329

Could you allocate a CVE id for this?

Thank you && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team

P.S.: The issue is different / unrelated than similar
      recent CGI.pm, CVE-2012-5526, flaw (the presence
      / absence of the CGI.pm CVE-2012-5526 fix doesn't
      have impact on it).

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.