Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Ubuntu 10.04 LTS USN-996-1 Critical: Mako Cross-Site Scripting

Ubuntu Large Esm H500
It was discovered that Mako incorrectly filtered single-quote characters when performing html filtering. An attacker could utilize this to perform cross-site scripting attacks.
==========================================================Ubuntu Security Notice USN-996-1         September 29, 2010
mako vulnerability
CVE-2010-2480
==========================================================
A security issue affects the following Ubuntu releases:

Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 10.04 LTS:
  python-mako                     0.2.5-2ubuntu1.3

In general, a standard system update will make all the necessary changes.

Details follow:

It was discovered that Mako incorrectly filtered single-quote characters
when performing html filtering. An attacker could utilize this to perform
cross-site scripting attacks.


Updated packages for Ubuntu 10.04:

  Source archives:

          Size/MD5:     5622 9cc948447247736d5d37f2ada66f2e59
          Size/MD5:     1452 fd281df3c78bc4ca4fb2f1a96a5cf9c9
          Size/MD5:   228192 d8ca783630dc5e93970a2075532fa643

  Architecture independent packages:

          Size/MD5:   100918 0df79d97dbd23990c0bb3dbd85e8c5f0



Ubuntu 10.04 LTS USN-996-1 Critical: Mako Cross-Site Scripting

ubuntu
Calendar Grey September 29, 2010
Dist Ubuntu Esm H88
==========================================================Ubuntu Security Notice USN-996-1 September
It was discovered that Mako incorrectly filtered single-quote characters when performing html filtering

Summary

Update Instructions

References

Severity
critical
Lowest
Low
Medium
High
Critical

mako vulnerability

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here