USN967-1 : w3m vulnerability
Synopsis :
These remote packages are missing security patches :
- w3m
- w3m-img
Description :
Ludwig Nussel discovered w3m does not properly handle SSL/TLS
certificates with NULL characters in the certificate name. An
attacker could exploit this to perform a man in the middle
attack to view sensitive information or alter encrypted
communications. (CVE-2010-2074)
Solution :
Upgrade to :
- w3m-0.5.2-2.1ubuntu1.1 (Ubuntu 10.04)
- w3m-img-0.5.2-2.1ubuntu1.1 (Ubuntu 10.04)
Risk factor :
Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
original thread: only registered users with at least 25 hack challenge points can see links: click here in order to visit the hack challengeshttp://www.nessus.org/plugins/index.php?view=single&id=48283