CVE-2008-3422
Published: 31 July 2008
Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4) HtmlInputRadioButton (RenderAttributes), and (5) HtmlSelect (RenderChildren).
Priority
Status
Package | Release | Status |
---|---|---|
mono Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
feisty |
Ignored
(end of life, was needed)
|
|
gutsy |
Ignored
(end of life, was needed)
|
|
hardy |
Released
(1.2.6+dfsg-6ubuntu3.1)
|
|
intrepid |
Not vulnerable
(1.9.1+dfsg-4ubuntu2)
|
|
jaunty |
Not vulnerable
(2.0.1-4)
|
|
upstream |
Needs triage
|
|
Patches: other: http://n2.nabble.com/-PATCH--HTML-encode-attributes-that-might-need-encoding-td584193.html vendor: http://svn.debian.org/wsvn/pkg-mono/migrated-to-git/mono/trunk/debian/patches/fix_sloppy_attribute_encode_CVE-2008-3422.dpatch upstream: http://anonsvn.mono-project.com/viewvc?view=rev&revision=109349 upstream: http://anonsvn.mono-project.com/viewvc?view=rev&revision=109348 upstream: http://anonsvn.mono-project.com/viewvc?view=rev&revision=109358 upstream: http://anonsvn.mono-project.com/viewvc?view=rev&revision=110144 |