Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 25: php-horde-Horde-Mime-Viewer XSS Mitigation - Critical Threat

fedora
Calendar Grey September 13, 2016
Dist Fedora Esm H88
Horde MIME Viewer in Fedora 25 receives a security patch to block SVG rendering, addressing potential XSS vulnerabilities.
**Horde_Mime_Viewer 2.2.1** * [jan] SECURITY: Don't render SVG images in the browser to avoid XSS attacks (Reported by Dawid Gounski via Beyond Security's SecuriTeam Secure Disclos...

Summary

Provides rendering drivers for MIME data.

Update Information:

**Horde_Mime_Viewer 2.2.1** * [jan] SECURITY: Don't render SVG images in the browser to avoid XSS attacks (Reported by Dawid Gounski via Beyond Security's SecuriTeam Secure Disclosure program).

Change Log

References

Fedora Update Notification FEDORA-2016-f5fda29032 2016-09-13 18:03:12.614348
Name : php-horde-Horde-Mime-Viewer Product : Fedora 25 Version : 2.2.1 Release : 1.fc25 URL : http://pear.horde.org Summary : Horde MIME Viewer Library Description : Provides rendering drivers for MIME data.

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update php-horde-Horde-Mime-Viewer' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: php-horde-Horde-Mime-Viewer
Product: Fedora 25
Version: 2.2.1
Release: 1.fc25
Summary: Horde MIME Viewer Library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here