[Bug 1829764] Re: linux whois command contain xss

2019-05-21 Thread Ragnar Patel
changing from xss to uncompleted and inappropriate response when running malicious or some javascript palyload. ** Summary changed: - linux whois command contain xss + linux whois command contain inappropriate response -- You received this bug notification because you are a member of Ubuntu Bu

[Bug 1829764] Re: linux whois command contain xss

2019-05-20 Thread Tom Reynolds
Could you explain what seems to be the security impact here? Cross Site Scripting (XSS) is an attack which may be possible when data is interpreted by a HTML renderer without ensuring that data is properly escaped / encoded. The "whois" command does not render HTML, it is a command line utility.