[Japanese]

JVNDB-2012-000008

glucose 2 vulnerable to arbitrary script execution

Overview

glucose 2 is vulnerable to arbitrary script execution.

glucose 2 is an RSS reader. glucose 2 is vulnerable to arbitrary script execution which is inserted in RSS feed, due to the improper processing of RSS feed output.

Daiki Fukumori of Cyber Defense Institute, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

Base Metrics: 4.3 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None

Affected Products


glucose inc.
  • glucose 2 stages prior to 6.2

Impact

An arbitrary script may be executed on the vulnerable system.
Solution

[Update the software]
Update to the latest version according to the information provided by the developer.

According to the developer, there are no plans for glucose 2 to be updated or maintained. Therefore, it is recommended that users should consider to use a different product that provides similar functionality.
Vendor Information

glucose inc.
CWE (What is CWE?)

  1. Cross-site Scripting(CWE-79) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2012-0313
References

  1. JVN : JVN#65869891
  2. National Vulnerability Database (NVD) : CVE-2012-0313
Revision History

[2012/01/23]
  Web page was published