CVE-2012-5649

Publication date 23 May 2014

Last updated 24 July 2024


Ubuntu priority

Description

Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, related to Adobe Flash.

Read the notes from the security team

Status

Package Ubuntu Release Status
couchdb 12.10 quantal Ignored
12.04 LTS precise Ignored
11.10 oneiric Ignored
10.04 LTS lucid Ignored
8.04 LTS hardy Not in release

Notes


jdstrand

JSONP is disabled by default on Ubuntu 11.10 and later it isn't clear why the patch fixes the issue. Could apply patch to disable jsonp by default supported use of couchdb is not used in this manner on Ubuntu 10.04 LTS

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
couchdb