|
|||||||||||
|
Bug#453783: apache2: CVE-2007-4465
From: Paul Szabo <psz(at)maths.usyd.edu.au>
Date: Sat Dec 01 2007 - 05:44:15 EST
> This is actually a bug in MSIE, see CVE-2006-5152. Not a bug in IE only, I have a demo that exploits it under Firefox. (In fact my demo does not seem to work for IE, yet...) Not really related to CVE-2006-5152. In fact that is a non-issue: the CVE references my posts, but fails to reference my retraction http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/049828.html > ... no plan to backport ... it is of low impact. I do not think that XSS and cookie theft (thus access to all data protected by web login) is of low impact. > ... setting AddDefaultCharset also protects from the issue. Thanks for that other workaround: yes it seems to protect my machines. Now I am puzzled why AddDefaultCharset was commented out in my configs. Still puzzled why Apache did not mention these workarounds. Cheers, Paul Szabo psz(at)maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of Sydney Australia -- To UNSUBSCRIBE, email to debian-apache-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Sat Dec 1 06:16:04 2007 This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 02:59:06 EDT |
||||||||||
|
|||||||||||