Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian: DSA-126-1 Critical: Horde IMP Cross-Site Scripting Issue

debian
Calendar Grey April 16, 2002
Debian Logo
Critical XSS vulnerability patched in Horde and IMP. Refer to Debian Security Advisory DSA-127-2 for additional details.
A cross-site scripting (CSS) problem was discovered in Horde and IMP (a webbased IMAP mail package)

Summary

Package : imp
Problem type : cross-site scripting (CSS)
Debian-specific: no


A cross-site scripting (CSS) problem was discovered in Horde and IMP (a web
based IMAP mail package). This was fixed upstream in Horde version 1.2.8
and IMP version 2.2.8. The relevant patches have been back-ported to
version 1.2.6-0.potato.5 of the horde package and version 2.2.6-0.potato.5
of the imp package.

This release also fixes a bug introduced by the php security fix from
DSA-115-1: the php postgres support changed subtle which broke the
postgres support from imp.


wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.


Debian GNU/Linux 2.2 alias potato
---------------------------------

Potato was released for alpha, arm, i386, m68k, powerpc and sparc.

Source archives:

MD5 checksum: b77256b8029270a8de5240e8a5533cae

MD5 checksum: 85ec854ef905a906997088649a12d60c

MD5 checksum: e8c010d3227f4c55e5b5c68b9921aee5

MD5 checksum: a874af4a6ef5ef8b3e...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here