Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200502-16
https://security.gentoo.org/
Severity: Low
Title: ht://Dig: Cross-site scripting vulnerability
Date: February 13, 2005
Bugs: #80602
ID: 200502-16
Synopsis
=======
ht://Dig is vulnerable to cross-site scripting attacks.
Background
=========
ht://Dig is an HTTP/HTML indexing and searching system.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 www-misc/htdig < 3.1.6-r7 >= 3.1.6-r7
==========
Michael Krax discovered that ht://Dig fails to validate the 'config'
parameter before displaying an error message containing the parameter.
This flaw could allow an attacker to conduct cross-site scripting
attacks.
Impact
====...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.