GNU gnump3d Unspecified Cross-Site Scripting Vulnerability
BID:15341
Info
GNU gnump3d Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 15341 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3425 CVE-2005-3425 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2005 12:00AM |
| Updated: | Mar 19 2015 09:32AM |
| Credit: | Discovery credited to Steve Kemp. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Desktop 1.0 GNU gnump3d 2.9.5 GNU gnump3d 2.9.4 GNU gnump3d 2.9.3 GNU gnump3d 2.9.2 GNU gnump3d 2.9.1 GNU gnump3d 2.9 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
GNU gnump3d 2.9.6 |
Discussion
GNU gnump3d Unspecified Cross-Site Scripting Vulnerability
GNU gnump3d is prone to an unspecified cross-site scripting vulnerability. An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
This issue is similar to that discussed in BID 15226 (GNU gnump3d Error Page Cross-Site Scripting Vulnerability) but is a seperate issue.
GNU gnump3d is prone to an unspecified cross-site scripting vulnerability. An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
This issue is similar to that discussed in BID 15226 (GNU gnump3d Error Page Cross-Site Scripting Vulnerability) but is a seperate issue.
Exploit / POC
GNU gnump3d Unspecified Cross-Site Scripting Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
GNU gnump3d Unspecified Cross-Site Scripting Vulnerability
Solution:
Gentoo has released advisory GLSA 200511-05 to address this issue. Gentoo updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=media-sound/gnump3d-2.9.7"
SUSE has released advisory SUSE-SR:2005:027 to address this, and other issues in various packages, in various SUSE products. The advisory states that there are pending fixes for this issue in SUSE products. Please see the referenced advisory for further information.
SUSE advisory SUSE-SR:2005:028 is available to address various issues. Please see the referenced advisory for more information.
A fix is available:
GNU gnump3d 2.9
GNU gnump3d 2.9.1
GNU gnump3d 2.9.2
GNU gnump3d 2.9.3
GNU gnump3d 2.9.4
GNU gnump3d 2.9.5
Solution:
Gentoo has released advisory GLSA 200511-05 to address this issue. Gentoo updates may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=media-sound/gnump3d-2.9.7"
SUSE has released advisory SUSE-SR:2005:027 to address this, and other issues in various packages, in various SUSE products. The advisory states that there are pending fixes for this issue in SUSE products. Please see the referenced advisory for further information.
SUSE advisory SUSE-SR:2005:028 is available to address various issues. Please see the referenced advisory for more information.
A fix is available:
GNU gnump3d 2.9
-
GNU gnump3d v2.9.6
http://www.gnu.org/software/gnump3d/download.html#Download
GNU gnump3d 2.9.1
-
GNU gnump3d v2.9.6
http://www.gnu.org/software/gnump3d/download.html#Download
GNU gnump3d 2.9.2
-
GNU gnump3d v2.9.6
http://www.gnu.org/software/gnump3d/download.html#Download
GNU gnump3d 2.9.3
-
GNU gnump3d v2.9.6
http://www.gnu.org/software/gnump3d/download.html#Download
GNU gnump3d 2.9.4
-
GNU gnump3d v2.9.6
http://www.gnu.org/software/gnump3d/download.html#Download
GNU gnump3d 2.9.5
-
GNU gnump3d v2.9.6
http://www.gnu.org/software/gnump3d/download.html#Download
References
GNU gnump3d Unspecified Cross-Site Scripting Vulnerability
References:
References: