Upstream information

CVE-2008-0005 at MITRE

Description

mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.3
Vector AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None
SUSE Bugzilla entries: 353262 [RESOLVED / FIXED], 355888 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Server 11 SP1
  • apache2 >= 2.2.10-2.24.5
  • apache2-doc >= 2.2.10-2.24.5
  • apache2-example-pages >= 2.2.10-2.24.5
  • apache2-prefork >= 2.2.10-2.24.5
  • apache2-utils >= 2.2.10-2.24.5
  • apache2-worker >= 2.2.10-2.24.5
Patchnames:
SUSE Linux Enterprise Server 11 SP1 GA apache2
SUSE Linux Enterprise Server 11 SP2
  • apache2 >= 2.2.12-1.28.1
  • apache2-doc >= 2.2.12-1.28.1
  • apache2-example-pages >= 2.2.12-1.28.1
  • apache2-prefork >= 2.2.12-1.28.1
  • apache2-utils >= 2.2.12-1.28.1
  • apache2-worker >= 2.2.12-1.28.1
Patchnames:
SUSE Linux Enterprise Server 11 SP2 GA apache2
SUSE Linux Enterprise Server 11 SP3
  • apache2 >= 2.2.12-1.38.2
  • apache2-doc >= 2.2.12-1.38.2
  • apache2-example-pages >= 2.2.12-1.38.2
  • apache2-prefork >= 2.2.12-1.38.2
  • apache2-utils >= 2.2.12-1.38.2
  • apache2-worker >= 2.2.12-1.38.2
Patchnames:
SUSE Linux Enterprise Server 11 SP3 GA apache2
SUSE Linux Enterprise Server 11 SP4
  • apache2 >= 2.2.12-1.51.52.1
  • apache2-doc >= 2.2.12-1.51.52.1
  • apache2-example-pages >= 2.2.12-1.51.52.1
  • apache2-prefork >= 2.2.12-1.51.52.1
  • apache2-utils >= 2.2.12-1.51.52.1
  • apache2-worker >= 2.2.12-1.51.52.1
Patchnames:
SUSE Linux Enterprise Server 11 SP4 GA apache2
SUSE Linux Enterprise Software Development Kit 11 SP4
  • apache2 >= 2.2.12-1.51.52.1
  • apache2-devel >= 2.2.12-1.51.52.1
  • apache2-doc >= 2.2.12-1.51.52.1
  • apache2-example-pages >= 2.2.12-1.51.52.1
  • apache2-prefork >= 2.2.12-1.51.52.1
  • apache2-utils >= 2.2.12-1.51.52.1
  • apache2-worker >= 2.2.12-1.51.52.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 11 SP4 GA apache2
Novell Linux Desktop 9 SDK for x86
Novell Linux Desktop 9 SDK for x86_64
  • apache2 >= 2.0.59-1.8
  • apache2-devel >= 2.0.59-1.8
  • apache2-prefork >= 2.0.59-1.8
  • apache2-worker >= 2.0.59-1.8
core9.s390
core9.x86
YOU Patch Nr: 12124
Novell Linux Desktop 9 for x86
Novell Linux Desktop 9 for x86_64
  • libapr0 >= 2.0.59-1.8
core9.s390
core9.x86
YOU Patch Nr: 12124
Open Enterprise Server
  • apache2 >= 2.0.59-1.8
  • apache2-devel >= 2.0.59-1.8
  • apache2-doc >= 2.0.59-1.8
  • apache2-example-pages >= 2.0.59-1.8
  • apache2-prefork >= 2.0.59-1.8
  • apache2-worker >= 2.0.59-1.8
  • libapr0 >= 2.0.59-1.8
core9.s390
core9.x86
YOU Patch Nr: 12124
Novell Linux Desktop 9 SDK for x86
Novell Linux Desktop 9 SDK for x86_64
  • apache >= 1.3.29-71.26
  • apache-devel >= 1.3.29-71.26
core9.x86
core9.s390
YOU Patch Nr: 12125
Open Enterprise Server
  • apache >= 1.3.29-71.26
  • apache-devel >= 1.3.29-71.26
  • apache-doc >= 1.3.29-71.26
  • apache-example-pages >= 1.3.29-71.26
  • mod_ssl >= 2.8.16-71.26
core9.x86
core9.s390
YOU Patch Nr: 12125
SUSE LINUX 10.1
  • apache2 >= 2.2.3-16.17.3
  • apache2-devel >= 2.2.3-16.17.3
  • apache2-doc >= 2.2.3-16.17.3
  • apache2-example-pages >= 2.2.3-16.17.3
  • apache2-prefork >= 2.2.3-16.17.3
  • apache2-worker >= 2.2.3-16.17.3