Candidate: CVE-2012-6637 PublicDate: 2014-03-03 04:50:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6637 http://www.openwall.com/lists/oss-security/2014/02/07 Description: Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as an initial substring. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_cordova-ubuntu: upstream_cordova-ubuntu: needs-triage lucid_cordova-ubuntu: DNE precise_cordova-ubuntu: DNE precise/esm_cordova-ubuntu: DNE quantal_cordova-ubuntu: DNE saucy_cordova-ubuntu: ignored (reached end-of-life) trusty_cordova-ubuntu: ignored (reached end-of-life) trusty/esm_cordova-ubuntu: DNE (trusty was needed) utopic_cordova-ubuntu: ignored (reached end-of-life) vivid_cordova-ubuntu: ignored (reached end-of-life) vivid/stable-phone-overlay_cordova-ubuntu: DNE vivid/ubuntu-core_cordova-ubuntu: DNE wily_cordova-ubuntu: ignored (reached end-of-life) xenial_cordova-ubuntu: DNE yakkety_cordova-ubuntu: DNE zesty_cordova-ubuntu: DNE artful_cordova-ubuntu: DNE bionic_cordova-ubuntu: DNE cosmic_cordova-ubuntu: DNE disco_cordova-ubuntu: DNE eoan_cordova-ubuntu: DNE focal_cordova-ubuntu: DNE groovy_cordova-ubuntu: DNE hirsute_cordova-ubuntu: DNE impish_cordova-ubuntu: DNE jammy_cordova-ubuntu: DNE devel_cordova-ubuntu: DNE Patches_cordova-ubuntu-3.4: upstream_cordova-ubuntu-3.4: needs-triage lucid_cordova-ubuntu-3.4: DNE precise_cordova-ubuntu-3.4: DNE precise/esm_cordova-ubuntu-3.4: DNE quantal_cordova-ubuntu-3.4: DNE saucy_cordova-ubuntu-3.4: DNE trusty_cordova-ubuntu-3.4: ignored (reached end-of-life) trusty/esm_cordova-ubuntu-3.4: DNE (trusty was needed) utopic_cordova-ubuntu-3.4: ignored (reached end-of-life) vivid_cordova-ubuntu-3.4: ignored (reached end-of-life) vivid/stable-phone-overlay_cordova-ubuntu-3.4: DNE vivid/ubuntu-core_cordova-ubuntu-3.4: DNE wily_cordova-ubuntu-3.4: ignored (reached end-of-life) xenial_cordova-ubuntu-3.4: ignored (end of standard support, was needed) yakkety_cordova-ubuntu-3.4: ignored (reached end-of-life) zesty_cordova-ubuntu-3.4: ignored (reached end-of-life) artful_cordova-ubuntu-3.4: ignored (reached end-of-life) bionic_cordova-ubuntu-3.4: DNE cosmic_cordova-ubuntu-3.4: DNE disco_cordova-ubuntu-3.4: DNE eoan_cordova-ubuntu-3.4: DNE focal_cordova-ubuntu-3.4: DNE groovy_cordova-ubuntu-3.4: DNE hirsute_cordova-ubuntu-3.4: DNE impish_cordova-ubuntu-3.4: DNE jammy_cordova-ubuntu-3.4: DNE devel_cordova-ubuntu-3.4: DNE