CVE-2018-0499: XSS
Published Jul 2, 2018
·Updated
A cross-site scripting vulnerability in queryparser/termgeneratorinternal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
Affected Software
7 affected componentsFixes available
ubuntu/xapian-core<1.4.4-2ubuntu0.1
1.4.4-2ubuntu0.1
ubuntu/xapian-core<1.4.5-1ubuntu0.1
1.4.5-1ubuntu0.1
ubuntu/xapian-core<1.4.6-1
1.4.6-1
debian/xapian-core
1.4.18-3+deb11u11.4.22-11.4.25-1
Xapian xapian-core<1.4.6
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
Remediation
Patch Available
Event History
Jul 2, 2018
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
Aug 5, 2024
Data Sourced
via Launchpad·03:36 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-0499?
CVE-2018-0499 has a medium severity level due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2018-0499?
To fix CVE-2018-0499, upgrade xapian-core to version 1.4.6 or higher.
3
Which versions of xapian-core are affected by CVE-2018-0499?
Versions of xapian-core prior to 1.4.6 are affected by CVE-2018-0499.
4
Is CVE-2018-0499 present in Ubuntu distributions?
Yes, CVE-2018-0499 is present in affected Ubuntu distributions before the remedial versions were released.
5
What types of vulnerabilities are associated with CVE-2018-0499?
CVE-2018-0499 is associated with cross-site scripting vulnerabilities.