GNU gnump3d Error Page Cross-Site Scripting Vulnerability
BID:15226
Info
GNU gnump3d Error Page Cross-Site Scripting Vulnerability
| Bugtraq ID: | 15226 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3424 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2005 12:00AM |
| Updated: | Oct 28 2005 12:00AM |
| Credit: | Discovery credited to Steve Kemp. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 GNU gnump3d 2.9.5 GNU gnump3d 2.9.4 GNU gnump3d 2.9.3 GNU gnump3d 2.9.2 GNU gnump3d 2.9.1 GNU gnump3d 2.9 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
GNU gnump3d 2.9.6 |
Discussion
GNU gnump3d Error Page Cross-Site Scripting Vulnerability
GNU gnump3d is prone to a cross-site scripting vulnerability. An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
GNU gnump3d is prone to a cross-site scripting vulnerability. An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
GNU gnump3d Error Page Cross-Site Scripting Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
GNU gnump3d Error Page Cross-Site Scripting Vulnerability
Solution:
Debian has released advisory DSA 877-1 and fixes to address this issue. Please see the referenced advisory for further information.
SUSE has released advisory SUSE-SR:2005:025 to address this, and other issues in various packages, in various SUSE products. The advisory states that there are pending fixes for this issue in SUSE products. Please see the referenced advisory for further information.
Gentoo has released advisory GLSA 200511-05 to address this issue. Gentoo updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=media-sound/gnump3d-2.9.7"
SUSE has released advisory SUSE-SR:2005:027 to address this, and other issues in various packages, in various SUSE products. The advisory states that there are pending fixes for this issue in SUSE products. Please see the referenced advisory for further information.
SUSE advisory SUSE-SR:2005:028 is available to address various issues. Please see the referenced advisory for more information.
A fix is available:
GNU gnump3d 2.9
GNU gnump3d 2.9.1
GNU gnump3d 2.9.2
GNU gnump3d 2.9.3
GNU gnump3d 2.9.4
GNU gnump3d 2.9.5
Solution:
Debian has released advisory DSA 877-1 and fixes to address this issue. Please see the referenced advisory for further information.
SUSE has released advisory SUSE-SR:2005:025 to address this, and other issues in various packages, in various SUSE products. The advisory states that there are pending fixes for this issue in SUSE products. Please see the referenced advisory for further information.
Gentoo has released advisory GLSA 200511-05 to address this issue. Gentoo updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=media-sound/gnump3d-2.9.7"
SUSE has released advisory SUSE-SR:2005:027 to address this, and other issues in various packages, in various SUSE products. The advisory states that there are pending fixes for this issue in SUSE products. Please see the referenced advisory for further information.
SUSE advisory SUSE-SR:2005:028 is available to address various issues. Please see the referenced advisory for more information.
A fix is available:
GNU gnump3d 2.9
-
GNU gnump3d v2.9.6
http://www.gnu.org/software/gnump3d/download.html#Download
GNU gnump3d 2.9.1
-
GNU gnump3d v2.9.6
http://www.gnu.org/software/gnump3d/download.html#Download
GNU gnump3d 2.9.2
-
GNU gnump3d v2.9.6
http://www.gnu.org/software/gnump3d/download.html#Download
GNU gnump3d 2.9.3
-
Debian gnump3d_2.9.3-1sarge2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/g/gnump3d/gnump3d_2.9.3-1 sarge2_all.deb -
GNU gnump3d v2.9.6
http://www.gnu.org/software/gnump3d/download.html#Download
GNU gnump3d 2.9.4
-
GNU gnump3d v2.9.6
http://www.gnu.org/software/gnump3d/download.html#Download
GNU gnump3d 2.9.5
-
GNU gnump3d v2.9.6
http://www.gnu.org/software/gnump3d/download.html#Download
References
GNU gnump3d Error Page Cross-Site Scripting Vulnerability
References:
References: