Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Gentoo: 200302-07 Critical: W3m HTML Quoting Issue Affects Security

gentoo
Calendar Grey February 17, 2003
Dist Gentoo Esm H88
Gentoo Linux security advisory 202204-12 addresses a critical flaw in the HTML handling of curl, offering vital update instructions for impacted users.
There is a Cross Site scripting vulnerability in w3m.

Summary


- ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200302-07
- ---------------------------------------------------------------------
DATE    : 2003-02-17 14:47 UTC

- ---------------------------------------------------------------------
From w3m release notes:
"Hironori SAKAMOTO found another security vulnerability in w3m 0.3.2.x that w3m will miss to escape html tag in img alt attribute, so malicious frame html may deceive you to access your local files, cookies and so on."
SOLUTION
It is recommended that all Gentoo Linux users who are running net-www/w3m upgrade to w3m-0.3.2.2 as follows:
emerge sync emerge -u w3m emerge clean
- --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - ---------------------------------------------------------------------

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : w3m
SUMMARY : missing HTML quoting
EXPLOIT : remote

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here