CVE-2011-4969
Publication date 30 January 2013
Last updated 24 July 2024
Ubuntu priority
Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.
Status
Package | Ubuntu Release | Status |
---|---|---|
jquery | 12.10 quantal |
Not affected
|
12.04 LTS precise |
Not affected
|
|
11.10 oneiric |
Fixed 1.6.2-1ubuntu2.2
|
|
10.04 LTS lucid |
Fixed 1.3.3-2ubuntu1.2
|
|
8.04 LTS hardy | Not in release |
References
Related Ubuntu Security Notices (USN)
- USN-1722-1
- jQuery vulnerability
- 13 February 2013