LWN.net Logo

mono: CRLF injection

Package(s):mono CVE #(s):CVE-2008-3906
Created:September 30, 2008 Updated:October 13, 2008
Description: From the CVE entry: CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.
Alerts:
rPath rPSA-2008-0286-1 2008-09-29
Mandriva MDVSA-2008:210 2007-10-03
Mandriva MDVSA-2008:210-1 2008-10-11

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds