PT-2002-3154 · Debian · W3M

Publicado

1970-01-01

·

Atualizado

2016-10-18

·

CVE-2002-1348

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions w3m versions prior to 0.3.2.2
Description The issue concerns multiple vulnerabilities in the w3m package of the Debian GNU/Linux operating system, which can lead to a breach of protected information confidentiality. These vulnerabilities can be exploited remotely. The problem is related to the improper escaping of HTML tags in the ALT attribute of an IMG tag, potentially allowing remote attackers to access files or cookies.
Recommendations For versions prior to 0.3.2.2, update to version 0.3.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-02566
BDU:2015-02684
BDU:2015-02685
BDU:2015-02929
BDU:2015-03067
BDU:2015-03291
CVE-2002-1348
DSA-249
DSA-251

Produtos afetados

W3M