CVE-2010-1330: XSS in the regular expression engine when processing invalid UTF-8 byte sequences
(updated )
The regular expression engine in this package, when $KCODE
is set to ‘u’, does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
References
Detect and mitigate CVE-2010-1330 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →