Release date:
Updated on:
Affected Systems:
NewsGator FeedDemon 3.1.0.9
Unaffected system:
NewsGator FeedDemon 4.1.0.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53858
FeedDemon is a popular Windows RSS reader that allows users to view and manage RSS feeds on their desktops.
FeedDemon 4.1.0.0 and earlier versions have the arbitrary script execution vulnerability. When the "feed preview" option is used, the error is handled when the HTML page is entered Based on the feed information, any script embedded in RSS/Atom feed may be executed in your Web browser.
<* Source: Daiki Fukumori
Link: http://jvn.jp/en/jp/JVN18397171/index.html
Http://jvndb.jvn.jp/en/contents/2012/JVNDB-2012-000056.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
NewsGator
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.feeddemon.com/