LWN.net Logo

couchdb: multiple vulnerabilities

Package(s):couchdb CVE #(s):CVE-2012-5649 CVE-2012-5650
Created:February 6, 2013 Updated:February 8, 2013
Description:

From the Red Hat bugzilla entries [1, 2]:

CVE-2012-5649: A security flaw was found in the way Apache CouchDB, a distributed, fault-tolerant and schema-free document-oriented database accessible via a RESTful HTTP/JSON API, processed certain JSON callback. A remote attacker could provide a specially-crafted JSON callback that, when processed could lead to arbitrary JSON code execution via Adobe Flash. (Couchdb advisory)

CVE-2012-5650: A DOM based cross-site scripting (XSS) flaw was found in the way browser-based test suite of Apache CouchDB, a distributed, fault-tolerant and schema-free document-oriented database accessible via a RESTful HTTP/JSON API, processed certain query parameters. A remote attacker could provide a specially-crafted web page that, when accessed could lead to arbitrary web script or HTML execution in the context of a CouchDB user session. (Couchdb advisory).

Alerts:
Fedora FEDORA-2013-1375 2013-02-02
Fedora FEDORA-2013-1387 2013-02-02
Mageia MGASA-2013-0040 2013-02-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds