CVE-2008-2168
Publication date 13 May 2008
Last updated 24 July 2024
Ubuntu priority
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
Status
Package | Ubuntu Release | Status |
---|---|---|
apache2 | 8.10 intrepid |
Not affected
|
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy |
Fixed 2.2.4-3ubuntu0.2
|
|
7.04 feisty | Ignored end of life, was needed | |
6.06 LTS dapper |
Fixed 2.0.55-4ubuntu2.4
|
Patch details
Package | Patch details |
---|---|
apache2 |