CVE-2008-5917 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5917): Cross-site scripting (XSS) vulnerability in the XSS filter (framework/Text_Filter/Filter/xss.php) in Horde Application Framework 3.2.2 and 3.3, when Internet Explorer is being used, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to style attributes.
Web-apps, hello?
+*horde-3.3.4 (24 Aug 2009) + + 24 Aug 2009; Alex Legler <a3li@gentoo.org> -horde-3.3.ebuild, + +horde-3.3.4.ebuild: + Non-maintainer commit: Version bump for security bug #256125 and bug + #262978. Removing unneded vulnerable version. +
Arches, please test and mark stable: =www-apps/horde-3.3.4 Target keywords : "alpha amd64 hppa ppc sparc x86"
amd64 stable
x86 stable
Stable on alpha.
Stable for HPPA.
sparc stable
ppc stable
GLSA with bug 262978.
GLSA 200909-14