Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6110 to the following vulnerability: Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6 allows remote attackers to inject arbitrary web script or HTML via the sort parameter. References: http://sourceforge.net/mailarchive/forum.php?thread_name=200709251310.55835.mskibbe%40suse.de&forum_name=htdig-dev
Created attachment 271081 [details] Patch from Michael Skibbe (reporter of the issue) Replaces error message: No such sort method: `<user supplied input here>' with simple: invalid sort method
Patch looks fine
Fixed in all affected products: Red Hat Enterprise Linux http://rhn.redhat.com/errata/RHSA-2007-1095.html Fedora https://admin.fedoraproject.org/updates/F7/FEDORA-2007-3907 https://admin.fedoraproject.org/updates/F8/FEDORA-2007-3958