Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: DSA 164-1 Severe: Mhonarc Cross Site Scripting Vulnerability

debian
Calendar Grey September 9, 2002
Debian Logo
Address cross-site scripting threats in mhonarc as outlined in Debian DSA 163-1. Upgrading your system is strongly recommended to protect against possible risks.
When processingmaliciously crafted mails of type text/html, mhonarc, does notdeactivate all scripting parts properly.

Summary

Jason Molenda and Hiromitsu Takagi found ways to exploit cross site
scripting bugs in mhonarc, a mail to HTML converter. When processing
maliciously crafted mails of type text/html, mhonarc, does not
deactivate all scripting parts properly. This is fixed in upstream
version 2.5.3.

If you are worried about security, it is recommended that you disable
support of text/html messages in your mail archives. There is no
guarantee that the mhtxthtml.pl library is robust enough to eliminate
all possible exploits that can occur with HTML data.

To exclude HTML data, you can use the MIMEEXCS resource. For example:


text/html
text/x-html


The use of "text/x-html" is probably not used any more, but is good to
include it, just-in-case.

If you are concerend that this could block out the entire contents of
some messages, then you could do the following instead:


text/html; m2h_text_plain::filter; mhtxtplain.pl
text/x-html; m2h_text_plain::filter; mhtxtplain.pl


This treats the HTML as text/plain.

...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: mhonarc

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here