Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 513
Alerts This Week
Warning Icon 1 513

Gentoo: GLSA 200502-16 Low Severity: ht://Dig Cross-Site Scripting

gentoo
Calendar Grey February 13, 2005
Scroller Gentoo
The ht://Dig toolkit on Gentoo has identified a critical vulnerability to cross-site scripting exploits, necessitating an urgent update to safeguard users' security.
ht://Dig is vulnerable to cross-site scripting attacks.

Summary

Gentoo Linux Security Advisory GLSA 200502-16 https://security.gentoo.org/ Severity: Low Title: ht://Dig: Cross-site scripting vulnerability Date: February 13, 2005 Bugs: #80602 ID: 200502-16

Synopsis ======= ht://Dig is vulnerable to cross-site scripting attacks.
Background ========= ht://Dig is an HTTP/HTML indexing and searching system.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-misc/htdig < 3.1.6-r7 >= 3.1.6-r7
========== Michael Krax discovered that ht://Dig fails to validate the 'config' parameter before displaying an error message containing the parameter. This flaw could allow an attacker to conduct cross-site scripting attacks.
Impact ====...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
low
Lowest
Low
Medium
High
Critical

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround