LWN.net Logo

apache: cross-site scripting

Package(s):apache CVE #(s):CVE-2012-2687
Created:October 2, 2012 Updated:April 5, 2013
Description: From the CVE entry:

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.

Alerts:
Mandriva MDVSA-2012:154-1 2012-10-01
Mageia MGASA-2012-0280 2012-10-06
Ubuntu USN-1627-1 2012-11-08
Oracle ELSA-2013-0130 2013-01-12
Scientific Linux SL-http-20130116 2013-01-16
openSUSE openSUSE-SU-2013:0245-1 2013-02-05
openSUSE openSUSE-SU-2013:0243-1 2013-02-05
openSUSE openSUSE-SU-2013:0248-1 2013-02-05
Fedora FEDORA-2013-1661 2013-02-12
Red Hat RHSA-2013:0512-02 2013-02-21
Oracle ELSA-2013-0512 2013-02-25
Scientific Linux SL-http-20130228 2013-02-28
CentOS CESA-2013:0512 2013-03-09
openSUSE openSUSE-SU-2013:0629-1 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds