CVE-2010-4803
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
03/05/2011
Last modified:
11/04/2025
Description
Mojolicious before 0.999927 does not properly implement HMAC-MD5 checksums, which has unspecified impact and remote attack vectors.
Impact
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:mojolicious:mojolicious:*:*:*:*:*:*:*:* | 0.999926 (including) | |
cpe:2.3:a:mojolicious:mojolicious:0.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.8.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.8.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.8.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.8.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.8.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.9:*:*:*:*:*:*:* | ||
cpe:2.3:a:mojolicious:mojolicious:0.8006:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622952
- http://cpansearch.perl.org/src/KRAIH/Mojolicious-1.20/Changes
- http://www.debian.org/security/2011/dsa-2239
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622952
- http://cpansearch.perl.org/src/KRAIH/Mojolicious-1.20/Changes
- http://www.debian.org/security/2011/dsa-2239