-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory GLSA 200802-03
https://security.gentoo.org/
Severity: Normal
Title: Horde IMP: Security bypass
Date: February 11, 2008
Bugs: #205377
ID: 200802-03
Synopsis
=======
Insufficient checks in Horde may allow a remote attacker to bypass
security restrictions.
Background
=========
Horde IMP provides a web-based access to IMAP and POP3 mailboxes.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 www-apps/horde-imp < 4.1.6 >= 4.1.6
==========
Ulf Harnhammar, Secunia Research discovered that the "frame" and
"frameset" HTML tags are not properly filtered out. He also reported
that certain HTT...Read the Full Advisory
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.