First published: Fri Jan 13 2012(Updated: )
CRLF injection vulnerability in Cogent DataHub 7.1.2 and earlier, Cascade DataHub 6.4.20 and earlier, and OPC DataHub 6.4.20 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cogent Datahub | <=6.4.20 | |
Cogent Datahub | <=7.1.2 | |
Cogent Datahub | =7.0 | |
Cogent Datahub | =7.0.2 | |
Cogent Datahub | =7.1.0 | |
Cogent Datahub | =7.1.1 | |
Cogent Datahub | =7.1.1.63 | |
Cogent Datahub | <=6.4.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0310 is considered a medium severity vulnerability due to its potential for HTTP response splitting attacks.
To fix CVE-2012-0310, update to the latest version of Cogent DataHub or apply patches that mitigate the CRLF injection vulnerability.
CVE-2012-0310 affects Cogent DataHub versions 7.1.2 and earlier, Cascade DataHub versions 6.4.20 and earlier, and OPC DataHub versions 6.4.20 and earlier.
CVE-2012-0310 can facilitate HTTP response splitting attacks by allowing remote attackers to inject arbitrary HTTP headers.
In the context of CVE-2012-0310, CRLF injection refers to the ability to insert carriage return and line feed characters to manipulate HTTP responses.