Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 53862
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Lance Albertson <ramereth@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 53862 depends on: Show dependency tree
Bug 53862 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-06-13 23:37 0000
Excerpt from my SANS email:

04.23.34 CVE: Not Available
Platform: Web Application
Title: Horde IMP Input Validation Vulnerability
Description: Horde IMP is a web-based IMAP email interface written in
PHP. Insufficient sanitization of email messages that contain
malicious HTML or script code expose an arbitrary HTML injection and
script execution issue. All current releases in the 3.x branch are
affected.
Ref: http://www.horde.org/imp/3.2/

I don't see anything specific on their site about what exactly causes this (might be in the Changlog when you download it). Version 3.2.4 is in portage, but marked ~arch on all arch's. Bug #53400 was the initial bug for getting it into portage, but no mention of the security fix.

------- Comment #1 From SpanKY 2004-06-14 04:58:54 0000 -------
moved 3.2.4 to stable and removed 3.2.3

------- Comment #2 From Sune Kloppenborg Jeppesen 2004-06-15 11:43:04 0000 -------
GLSA drafted. Security please review.

Bugtraq announcement can be found here:

http://www.securityfocus.com/bid/10501/

Note: bug number 53862 does not appear in the ChangeLog

------- Comment #3 From Kurt Lieber 2004-06-16 06:31:27 0000 -------
glsa 200406-11

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug