Summary: | <www-apps/horde-3.3.9: Cross Site Scripting Vulnerability (CVE-2010-3077) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Tim Sammut (RETIRED) <underling> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | a3li |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://git.horde.org/diff.php/horde/util/icon_browser.php?rt=horde-git&r1=a978a35c3e95e784253508fd4333d2fbb64830b6&r2=9342addbd2b95f184f230773daa4faf5ef6d65e9 | ||
Whiteboard: | B4 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Tim Sammut (RETIRED)
![]() Fixed in 3.3.9 as per http://lists.horde.org/archives/announce/2010/000557.html. Arches, please test and mark stable: =www-apps/horde-3.3.9 Target keywords : "alpha amd64 hppa ppc sparc x86" I tested the following things together on x86 with apache (dev-lang/php-5.2.14) and my dovecot imap server. I've seen no problems at all! :-) www-apps/horde-3.3.9 Bug #336319 www-apps/horde-imp-4.3.8 Bug #307759 www-apps/horde-dimp-1.1.5 Bug #307759 www-apps/horde-gollem-1.1.2 Bug #339168 Stable on alpha. amd64 done x86 stable, thanks Andreas ppc done sparc stable Stable for HPPA. Thanks, folks. GLSA Vote: No, XSS. XSS in webapp -> closing noglsa. |