Cross-site request forgery in Debian Linux and Opensuse - CVE-2014-2327
Published: April 23, 2014 / Updated: August 10, 2020
SUSE
Debian Linux
Opensuse
Detailed vulnerability description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.
How to mitigate CVE-2014-2327
Sources
- http://jvn.jp/en/jp/JVN55076671/index.html
- http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-002239.html
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00034.html
- http://secunia.com/advisories/59203
- http://www.debian.org/security/2014/dsa-2970
- http://www.securityfocus.com/archive/1/531588
- http://www.securityfocus.com/bid/66392
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742768
- https://security.gentoo.org/glsa/201509-03