Wind River Support Network

HomeDefectsLIN5-16281
Fixed

LIN5-16281 : Security Advisory - apache - CVE-2012-2687

Created: Sep 2, 2012    Updated: Dec 19, 2017
Resolved Date: Apr 22, 2014
Previous ID: LIN2-13251
Found In Version: 5.0
Fix Version: 5.0.1.14
Severity: Low
Applicable for: Wind River Linux 5
Component/s: Userspace

Description

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2687

Workaround

Unknown

Steps to Reproduce

Unknown

Other Downloads


Live chat
Online