Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53324
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 249-1 (w3mmee)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to w3mmee
announced via advisory DSA 249-1.

Hironori Sakamoto, one of w3m developers, found two security
vulnerabilities in w3m and associated programs. The w3m browser does
not properly escape HTML tags in frame contents and img alt
attributes. A malicious HTML frame or img alt attribute may deceive a
user to send his local cookies which are used for configuration. The
information is not leaked automatically, though.

For the stable distribution (woody) these problems have been fixed in
version 0.3.p23.3-1.5. Please note that the update also contains an
important patch to make the program work on the powerpc platform again.

The old stable distribution (potato) is not affected by these
problems.

For the unstable distribution (sid) these problems have been fixed in
version 0.3.p24.17-3 and later.

We recommend that you upgrade your w3mmee packages.


Solution:
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20249-1

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-1335
BugTraq ID: 6793
http://www.securityfocus.com/bid/6793
Debian Security Information: DSA-249 (Google Search)
http://www.debian.org/security/2003/dsa-249
Debian Security Information: DSA-250 (Google Search)
http://www.debian.org/security/2003/dsa-250
Debian Security Information: DSA-251 (Google Search)
http://www.debian.org/security/2003/dsa-251
http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.009.html
http://www.osvdb.org/6981
http://www.redhat.com/support/errata/RHSA-2003-044.html
http://www.redhat.com/support/errata/RHSA-2003-045.html
http://secunia.com/advisories/8015
http://secunia.com/advisories/8016
http://secunia.com/advisories/8031
http://secunia.com/advisories/8053
XForce ISS Database: w3m-html-frame-xss(10842)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10842
Common Vulnerability Exposure (CVE) ID: CVE-2002-1348
BugTraq ID: 6794
http://www.securityfocus.com/bid/6794
Bugtraq: 20030217 GLSA: w3m (Google Search)
http://marc.info/?l=bugtraq&m=104552193927323&w=2
http://www.iss.net/security_center/static/11266.php
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.