CVE-2010-2480

Publication date 2 July 2010

Last updated 24 July 2024


Ubuntu priority

Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.

Status

Package Ubuntu Release Status
mako 11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Fixed 0.2.5-2ubuntu1.3
9.10 karmic Ignored end of life
9.04 jaunty Ignored end of life
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Not in release

References

Related Ubuntu Security Notices (USN)

    • USN-996-1
    • Mako vulnerability
    • 29 September 2010

Other references