CVE-2005-3424: XSS
Published Nov 1, 2005
·Updated
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.5 allows remote attackers to inject arbitrary web script or HTML via 404 error pages, a different vulnerability than CVE-2005-3425.
Affected Software
15 affected components
GNU gnump3d=2.9
GNU gnump3d=2.4
GNU gnump3d=2.5b
GNU gnump3d=2.9.2
GNU gnump3d=2.9.4
GNU gnump3d=2.3
GNU gnump3d=2.7
GNU gnump3d=2.9.3
GNU gnump3d=2.2
GNU gnump3d=2.1
GNU gnump3d=2.0
GNU gnump3d=2.5
GNU gnump3d=2.8
GNU gnump3d=2.6
GNU gnump3d=2.9.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Nov 1, 2005
CVE Published
10:02 PM
Nov 2, 2005
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3424?
CVE-2005-3424 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2005-3424?
To fix CVE-2005-3424, upgrade GNUMP3D to version 2.9.5 or later to mitigate the XSS vulnerability.
3
Which versions of GNUMP3D are affected by CVE-2005-3424?
CVE-2005-3424 affects GNUMP3D versions 2.0 through 2.9.4.
4
What types of attacks can CVE-2005-3424 facilitate?
CVE-2005-3424 can facilitate cross-site scripting attacks, allowing attackers to inject arbitrary web scripts or HTML.
5
Is CVE-2005-3424 related to any other vulnerabilities?
Yes, CVE-2005-3424 is related to CVE-2005-3425, but it addresses a different aspect of vulnerability regarding 404 error pages.