Lucene search

K
mageiaGentoo FoundationMGASA-2015-0168
HistoryApr 24, 2015 - 12:14 a.m.

Updated ntop packages fix CVE-2014-4165

2015-04-2400:14:25
Gentoo Foundation
advisories.mageia.org
14

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

66.4%

Updated ntop package fixes security vulnerability: Lack of filtering in the title parameter of links to rrdPlugin allowed cross-site-scripting (XSS) attacks against users of the web interface (CVE-2014-4165).

OSVersionArchitecturePackageVersionFilename
Mageia4noarchntop< 5.0.1-4.1ntop-5.0.1-4.1.mga4

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

66.4%