As noted in this report to oss-security [1], a flaw exists in the apt-cacher-ng server, and an inside attacker (on the LAN with knowledge of the server's address), could trick a user into visiting, or redirect them to, a manipulated URL that would cause the cross-site scripting attack. A proposed fix has been made [2]. [1] http://seclists.org/oss-sec/2014/q2/602 [2] http://anonscm.debian.org/gitweb/?p=apt-cacher-ng/apt-cacher-ng.git;a=commitdiff;h=6f08e6a3995d1bed4e837889a3945b6dc650f6ad
Created apt-cacher-ng tracking bugs for this issue: Affects: fedora-20 [bug 1111808]
MITRE assigned CVE-2014-4510 to this issue: http://seclists.org/oss-sec/2014/q2/603
apt-cacher-ng-0.7.26-2.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.