LWN.net Logo

man2html: cross-site scripting

Package(s):man2hhtml CVE #(s):CVE-2011-2770
Created:November 7, 2011 Updated:November 9, 2011
Description:

From the Debian advisory:

Tim Starling discovered that the Debian-native CGI wrapper for man2html, a program to convert UNIX man pages to HTML, is not properly escaping user-supplied input when displaying various error messages. A remote attacker can exploit this flaw to conduct cross-site scripting (XSS) attacks.

Alerts:
Debian DSA-2335-1 2011-11-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds