First published: Mon Nov 19 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository commit access to inject arbitrary web script or HTML via the "function name" line.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ViewVC | >=1.0.0<1.0.13 | |
ViewVC | >=1.1.0<1.1.16 | |
Debian GNU/Linux | =6.0 | |
Debian GNU/Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4533 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS).
To fix CVE-2012-4533, upgrade to ViewVC version 1.0.13 or 1.1.16 or later.
CVE-2012-4533 affects authenticated users with commit access in ViewVC version 1.0.x before 1.0.13 and 1.1.x before 1.1.16.
CVE-2012-4533 enables an attacker to inject arbitrary web scripts or HTML, potentially leading to exploitation through cross-site scripting.
Yes, CVE-2012-4533 can affect Debian Linux systems running vulnerable versions of ViewVC.