Bug#694279: libdancer-perl: Cookie name CRLF injection

2013-06-03 Thread Niko Tyni
tag 694279 fixed-upstream thanks On Sun, Nov 25, 2012 at 12:49:25AM +0100, Salvatore Bonaccorso wrote: > Package: libdancer-perl > Severity: important > Tags: security > Similar to #693421, CVE-2012-5526 it was reported[1] that > libdancer-perl's Dancer::Cookie also do not validate cookie name fo

Bug#694279: libdancer-perl: Cookie name CRLF injection

2012-11-24 Thread Salvatore Bonaccorso
Package: libdancer-perl Severity: important Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi Similar to #693421, CVE-2012-5526 it was reported[1] that libdancer-perl's Dancer::Cookie also do not validate cookie name for CRLF and other invalid symbols in headers. A patch however