Release date:
Updated on: 2013-01-19
Affected Systems:
Apache Group CouchDB 1.0.2
Apache Group CouchDB 1.0.1
Apache Group CouchDB 1.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57314
CVE (CAN) ID: CVE-2012-5649
Apache CouchDB is a document-oriented database management system.
Apache CouchDB 1.0.3, 1.1.1, 1.2.0 and earlier versions have security vulnerabilities when processing certain JSON callbacks. Attackers can execute arbitrary JSON code through specially crafted JSON echo and Adobe Flash.
<* Source: Jan Lehnardt
Link: https://bugzilla.redhat.com/show_bug.cgi? CVE-2012-5649
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/