First published: Wed Feb 19 2014(Updated: )
It was reported [1],[2] that the CGI::Application perl module suffered from a flaw where, in certain cases, it would unexpectedly dump a complete set of web query data and server environment information as an error page. This could allow unintended disclosure of sensitive information. A suggested fix is available [3] and the commit that caused the problem [4] was most likely introduced in version 4.19. [1] <a href="https://rt.cpan.org/Public/Bug/Display.html?id=84403">https://rt.cpan.org/Public/Bug/Display.html?id=84403</a> [2] <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=739505">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=739505</a> [3] <a href="https://github.com/markstos/CGI--Application/pull/15">https://github.com/markstos/CGI--Application/pull/15</a> [4] <a href="https://github.com/markstos/CGI--Application/commit/61d327646f01fe">https://github.com/markstos/CGI--Application/commit/61d327646f01fe</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libcgi-application-perl | 4.61-1 4.61+~1.21+~1.00+~1.01-1 | |
Perl Cgi Application Module | <=4.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.