First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 90365
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Jean-François Brunette (RETIRED) <formula7@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 90365 depends on: Show dependency tree
Bug 90365 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-04-25 06:48 0000
Description:
A vulnerability has been reported in ***, which can be exploited by malicious people to conduct cross-site scripting attacks.

Input passed to a parent frame's page title is not properly sanitised before being returned to users. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of a vulnerable site.

------- Comment #1 From Jean-François Brunette (RETIRED) 2005-04-25 06:49:28 0000 -------
*** Bug 90364 has been marked as a duplicate of this bug. ***

------- Comment #2 From Jean-François Brunette (RETIRED) 2005-04-25 06:52:14 0000 -------
Update to version 1.2.3.
http://www.horde.org/chora/download/

Update to version 2.2.2.
http://www.horde.org/forwards/download/

Update to version 2.1.2.
http://www.horde.org/accounts/download/

Update to version 1.1.3.
http://www.horde.org/nag/download/

Update to version 1.1.4.
http://www.horde.org/mnemo/download/

Update to version 2.2.2.
http://www.horde.org/vacation/download/

------- Comment #3 From Jean-François Brunette (RETIRED) 2005-04-25 08:19:19 0000 -------
Secunia just released new advisories... horde-{imp|turba|passwd|} are also
vulnerable

------- Comment #4 From Jean-François Brunette (RETIRED) 2005-04-25 08:22:01 0000 -------
Let's say horde-* 

------- Comment #5 From Sune Kloppenborg Jeppesen 2005-04-25 12:28:04 0000 -------
vapier please advise.

------- Comment #6 From SpanKY 2005-04-25 19:59:50 0000 -------
all versions are bumped and in portage now, keyworded and all that jazz

------- Comment #7 From Thierry Carrez (RETIRED) 2005-04-26 07:42:23 0000 -------
Ready for GLSA vote apparently

------- Comment #8 From Thierry Carrez (RETIRED) 2005-04-28 09:39:46 0000 -------
I vote NO

------- Comment #9 From Sune Kloppenborg Jeppesen 2005-04-28 12:52:37 0000 -------
We used to issue GLSAs for XSS issues in Squirrelmail, I see no reason to do
otherwise with horde-*(imp) -> voting YES.

http://marc.theaimsgroup.com/?l=horde-announce&r=1&b=200504&w=2

------- Comment #10 From Thierry Carrez (RETIRED) 2005-04-29 11:22:51 0000 -------
Reversing vote, after all there are plenty :)

------- Comment #11 From Luke Macken (RETIRED) 2005-05-01 09:11:26 0000 -------
GLSA 200505-01

First Last Prev Next    No search results available      Search page      Enter new bug