CVE-2007-2291: CRLF Injection
Published Apr 26, 2007
·Updated
CRLF injection vulnerability in the Digest Authentication support for Microsoft Internet Explorer 7.0.5730.11 allows remote attackers to conduct HTTP response splitting attacks via a LF (%0a) in the username attribute.
Affected Software
1 affected component
Microsoft Internet Explorer=7.0.5730.11
Event History
Apr 26, 2007
CVE Published
08:19 PM
Apr 27, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2291?
The severity of CVE-2007-2291 is considered to be high due to the potential for HTTP response splitting attacks.
2
How do I fix CVE-2007-2291?
To fix CVE-2007-2291, it is recommended to upgrade to a newer version of Internet Explorer that is not affected by this vulnerability.
3
What systems are affected by CVE-2007-2291?
CVE-2007-2291 specifically affects Microsoft Internet Explorer version 7.0.5730.11.
4
What type of attack does CVE-2007-2291 enable?
CVE-2007-2291 enables remote attackers to conduct HTTP response splitting attacks via CRLF injection.
5
Can CVE-2007-2291 be exploited without authentication?
Yes, CVE-2007-2291 can be exploited by attackers without requiring authentication.