LWN.net Logo

empathy: cross-site scripting

Package(s):empathy CVE #(s):CVE-2011-3635 CVE-2011-4170
Created:October 28, 2011 Updated:November 18, 2011
Description: From the Ubuntu advisory:

It was discovered that a cross-site scripting (XSS) vulnerability in the Adium theme allows remote attackers to inject arbitrary javascript or HTML via a crafted nickname in XMPP group conversations.

Alerts:
openSUSE openSUSE-SU-2011:1257-1 2011-11-18
Ubuntu USN-1250-1 2011-10-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds