First published: Mon Jul 02 2018(Updated: )
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
Credit: security@debian.org security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xapian xapian-core | <1.4.6 | |
Canonical Ubuntu Linux | =17.10 | |
Canonical Ubuntu Linux | =18.04 | |
ubuntu/xapian-core | <1.4.4-2ubuntu0.1 | 1.4.4-2ubuntu0.1 |
ubuntu/xapian-core | <1.4.5-1ubuntu0.1 | 1.4.5-1ubuntu0.1 |
ubuntu/xapian-core | <1.4.6-1 | 1.4.6-1 |
debian/xapian-core | 1.4.18-3+deb11u1 1.4.22-1 1.4.25-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.