http://svn.apache.org/viewvc?view=rev&revision=603282
Fix CVE-2007-5000:
* modules/mappers/mod_imagemap.c (menu_header): Fix
cross-site-scripting issue by escaping the URI, and ensure that a
charset parameter is sent in the content-type to prevent
autodetection by broken browsers.
Reported by: JPCERT
A flaw was found in the Apache httpd mod_imagemap module. On sites where
mod_imagemap was enabled and an imagemap file was publicly available, a
cross-site scripting attack was possible. (CVE-2007-5000)
Comment 11Fedora Update System
2008-02-13 14:28:36 UTC
httpd-2.2.8-1.fc8 has been submitted as an update for Fedora 8
Comment 12Fedora Update System
2008-02-13 14:32:47 UTC
httpd-2.2.8-1.fc7 has been submitted as an update for Fedora 7
Comment 13Fedora Update System
2008-02-16 02:08:12 UTC
httpd-2.2.8-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Comment 14Fedora Update System
2008-02-16 02:10:54 UTC
httpd-2.2.8-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.