--------------------------------------------------------------------------------Fedora Update Notification
FEDORA-2019-ad02f64a79
2019-08-15 18:07:56.659694
--------------------------------------------------------------------------------Name        : squirrelmail
Product     : Fedora 30
Version     : 1.4.23
Release     : 1.fc30.20190710
URL         : https://www.squirrelmail.org/
Summary     : webmail client written in php
Description :
SquirrelMail is a basic webmail package written in PHP4. It
includes built-in pure PHP support for the IMAP and SMTP protocols, and
all pages render in pure HTML 4.0 (with no JavaScript) for maximum
compatibility across browsers.  It has very few requirements and is very
easy to configure and install.

--------------------------------------------------------------------------------Update Information:

updated to 1.4 branch snapshot containing several security fixes
--------------------------------------------------------------------------------ChangeLog:

* Wed Jul 10 2019 Michal Hlavinka  - 1.4.23-1.20190710
- squirrelmail updated to newer snapshot
--------------------------------------------------------------------------------References:

  [ 1 ] Bug #1616100 - CVE-2018-14955 squirrelmail: persistent XSS in message display via SVG animations [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=1616100
  [ 2 ] Bug #1616097 - CVE-2018-14954 squirrelmail: persistent XSS in message display the formaction attribute [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=1616097
  [ 3 ] Bug #1616094 - CVE-2018-14953 squirrelmail: persistent XSS in message display via a "

Fedora 30: squirrelmail FEDORA-2019-ad02f64a79

August 15, 2019
updated to 1.4 branch snapshot containing several security fixes

Summary

SquirrelMail is a basic webmail package written in PHP4. It

includes built-in pure PHP support for the IMAP and SMTP protocols, and

all pages render in pure HTML 4.0 (with no JavaScript) for maximum

compatibility across browsers. It has very few requirements and is very

easy to configure and install.

updated to 1.4 branch snapshot containing several security fixes

* Wed Jul 10 2019 Michal Hlavinka - 1.4.23-1.20190710

- squirrelmail updated to newer snapshot

[ 1 ] Bug #1616100 - CVE-2018-14955 squirrelmail: persistent XSS in message display via SVG animations [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1616100

[ 2 ] Bug #1616097 - CVE-2018-14954 squirrelmail: persistent XSS in message display the formaction attribute [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1616097

[ 3 ] Bug #1616094 - CVE-2018-14953 squirrelmail: persistent XSS in message display via a "

FEDORA-2019-ad02f64a79 2019-08-15 18:07:56.659694 Product : Fedora 30 Version : 1.4.23 Release : 1.fc30.20190710 URL : https://www.squirrelmail.org/ Summary : webmail client written in php Description : SquirrelMail is a basic webmail package written in PHP4. It includes built-in pure PHP support for the IMAP and SMTP protocols, and all pages render in pure HTML 4.0 (with no JavaScript) for maximum compatibility across browsers. It has very few requirements and is very easy to configure and install. updated to 1.4 branch snapshot containing several security fixes * Wed Jul 10 2019 Michal Hlavinka - 1.4.23-1.20190710 - squirrelmail updated to newer snapshot [ 1 ] Bug #1616100 - CVE-2018-14955 squirrelmail: persistent XSS in message display via SVG animations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1616100 [ 2 ] Bug #1616097 - CVE-2018-14954 squirrelmail: persistent XSS in message display the formaction attribute [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1616097 [ 3 ] Bug #1616094 - CVE-2018-14953 squirrelmail: persistent XSS in message display via a "

Change Log

References

Update Instructions

Severity
Product : Fedora 30
Version : 1.4.23
Release : 1.fc30.20190710
URL : https://www.squirrelmail.org/
Summary : webmail client written in php

Related News