LWN.net Logo

horizon: multiple vulnerabilities

Package(s):horizon CVE #(s):CVE-2012-2094 CVE-2012-2144
Created:May 7, 2012 Updated:May 9, 2012
Description: From the

Matthias Weckbecker discovered a cross-site scripting (XSS) vulnerability in Horizon via the log viewer refrash mechanism. If a user were tricked into viewing a specially crafted log message, a remote attacker could exploit this to modify the contents or steal confidential data within the same domain. (CVE-2012-2094)

Thomas Biege discovered a session fixation vulnerability in Horizon. An attacker could exploit this to potentially allow access to unauthorized information and capabilities. (CVE-2012-2144)

Alerts:
Ubuntu USN-1439-1 2012-05-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds