Summary: | mail-client/squirrelmail insecure file inclusion | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sune Kloppenborg Jeppesen (RETIRED) <jaervosz> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | eradicator |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | All | ||
URL: | http://www.squirrelmail.org/changelog.php | ||
Whiteboard: | C1 [glsa] jaervosz | ||
Package list: | Runtime testing required: | --- |
Description
Sune Kloppenborg Jeppesen (RETIRED)
![]() Probably better to wait for the official 1.4.4 on Monday. Eradicator: if you can't handle it on Monday, please tell us so that we find someone else to do the bump. I'll take care of it on monday. should be a simple renaming. Upstream still hasn't made a release... Ok, can youu find someone else to bump it for me. I am going to sleep now, leaving in the morning, and they still haven't made the release. Apparently this has been delayed until Friday. Two more issues: http://cvs.sf.net/viewcvs.py/squirrelmail/squirrelmail/src/webmail.php?r1=1.92.2.8&r2=1.92.2.6&only_with_tag=SM-1_4-STABLE CAN-2005-0103 for cross site scripting CAN-2005-0104 for code injection via unsanitised integer variable Hopefully they will release soon. 1.4.4 released, please bump. In CVS. Just need ppc to mark stable. Thx Jeremy. ppc please mark stable. GLSA drafted. Security please review. ppc please mark stable asap. stable on ppc sorry for the wait dada ppc Not yet ppc stable in CVS... SeJo / ppc-team, please fix your keyword SeJo markes ppc stable. Ready to send GLSA 200501-39 |