CVE-2010-0011: High severity uzbl Uzbl vulnerability
Published Feb 25, 2010
·Updated
The evaljs function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to execute arbitrary commands via JavaScript code.
Affected Software
1 affected component
uzbl Uzbl<=2009.12.22
Remediation
Patch Available
Event History
Feb 25, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0011?
CVE-2010-0011 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2010-0011?
To fix CVE-2010-0011, update Uzbl to version 2010.01.05 or later.
3
What are the potential impacts of CVE-2010-0011?
The impact of CVE-2010-0011 includes the ability for remote attackers to execute arbitrary commands on the affected system.
4
Which versions of Uzbl are affected by CVE-2010-0011?
Uzbl versions prior to 2010.01.05, specifically all versions up to 2009.12.22, are affected by CVE-2010-0011.
5
What component of Uzbl is vulnerable in CVE-2010-0011?
The eval_js function in uzbl-core.c is the component that is vulnerable in CVE-2010-0011.