Oval Definition:oval:com.redhat.rhsa:def:20071095
Revision Date:2007-12-03Version:636
Title:RHSA-2007:1095: htdig security update (Moderate)
Description:The ht://Dig system is a complete World Wide Web indexing and searching system for a small domain or intranet.

  • A cross-site scripting flaw was discovered in a htdig search page. An attacker could construct a carefully crafted URL, which once visited by an unsuspecting user, could cause a user's Web browser to execute malicious script in the context of the visited htdig search Web page. (CVE-2007-6110)

    Users of htdig are advised to upgrade to these updated packages, which contain backported patch to resolve this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-6110
    RHSA-2007:1095
    RHSA-2007:1095-01
    RHSA-2007:1095-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • htdig is earlier than 3:3.2.0b6-4.el4_6
  • AND htdig is signed with Red Hat redhatrelease2 key
  • htdig-web is earlier than 3:3.2.0b6-4.el4_6
  • AND htdig-web is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • htdig is earlier than 3:3.2.0b6-9.0.1.el5_1
  • AND htdig is signed with Red Hat redhatrelease2 key
  • htdig-web is earlier than 3:3.2.0b6-9.0.1.el5_1
  • AND htdig-web is signed with Red Hat redhatrelease2 key
  • BACK