First published: Wed Sep 12 2007(Updated: )
Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5 allows local users to inject arbitrary web script or HTML via a crafted (1) file or (2) process name, which triggers an Access Vector Cache (AVC) log entry in a log file used during composition of HTML documents for sealert.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux | =5.0 | |
redhat enterprise Linux desktop | =5 | |
SELinux Setroubleshoot | =2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5496 is considered a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2007-5496, update the SELinux Setroubleshoot software to a version beyond 2.0.5 that addresses this vulnerability.
CVE-2007-5496 affects users of SELinux Setroubleshoot version 2.0.5 on certain Red Hat Enterprise Linux and desktop versions.
CVE-2007-5496 can facilitate cross-site scripting (XSS) attacks, allowing local users to inject malicious web scripts.
No, CVE-2007-5496 is not a remote vulnerability; it requires local user access to exploit.