From the release notes: "This is a minor security release that fixes unescaped output in the tag cloud search script, and validates the Horde_Image driver name to prevent a possible local file inclusion vulnerability. All users are encouraged to upgrade to this release." Reproducible: Always Steps to Reproduce: Works for me with a renamed ebuild from the previous version.
Now 3.3.4 is out, any chance of getting this into Portage? ta!
Done for Security, bug 256125 and bug 262978.