Debian DSA-199-1 : mhonarc - XSS

medium Nessus Plugin ID 15036

Synopsis

The remote Debian host is missing a security-related update.

Description

Steven Christey discovered a cross site scripting vulnerability in mhonarc, a mail to HTML converter. Carefully crafted message headers can introduce cross site scripting when mhonarc is configured to display all headers lines on the web. However, it is often useful to restrict the displayed header lines to To, From and Subject, in which case the vulnerability cannot be exploited.

Solution

Upgrade the mhonarc package.

This problem has been fixed in version 2.5.2-1.2 for the current stable distribution (woody), in version 2.4.4-1.2 for the old stable distribution (potato) and in version 2.5.13-1 for the unstable distribution (sid).

See Also

http://www.debian.org/security/2002/dsa-199

Plugin Details

Severity: Medium

ID: 15036

File Name: debian_DSA-199.nasl

Version: 1.21

Type: local

Agent: unix

Published: 9/29/2004

Updated: 1/4/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:mhonarc, cpe:/o:debian:debian_linux:2.2, cpe:/o:debian:debian_linux:3.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/19/2002

Vulnerability Publication Date: 10/21/2002

Reference Information

CVE: CVE-2002-1307

BID: 6204

DSA: 199