CVE-2008-0005
Publication date 11 January 2008
Last updated 24 July 2024
Ubuntu priority
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
Status
Package | Ubuntu Release | Status |
---|---|---|
apache | 9.10 karmic | Not in release |
9.04 jaunty | Not in release | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
7.10 gutsy | Not in release | |
7.04 feisty | Ignored end of life, was needs-triage | |
6.10 edgy | Ignored end of life, was needs-triage | |
6.06 LTS dapper | Ignored end of life | |
apache2 | 9.10 karmic |
Not affected
|
9.04 jaunty |
Not affected
|
|
8.10 intrepid |
Not affected
|
|
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy |
Fixed 2.2.4-3ubuntu0.1
|
|
7.04 feisty |
Fixed 2.2.3-3.2ubuntu2.1
|
|
6.10 edgy |
Fixed 2.0.55-4ubuntu4.2
|
|
6.06 LTS dapper |
Fixed 2.0.55-4ubuntu2.3
|