oss-sec mailing list archives
CVE Request -- Horde IMP -- Multiple XSS flaws fixed in v5.0.18
From: Jan Lieskovsky <jlieskov () redhat com>
Date: Sat, 21 Jan 2012 11:44:08 +0100
Hello Kurt, Steve, vendors, Multiple XSS flaws were adressed in the v5.0.18 version of Horde IMP (from [1]): "[mms] SECURITY: Fix XSS vulnerabilities on the compose page (traditional view), the contacts popup window, and with certain IMAP mailbox names." References: [1] http://www.horde.org/apps/imp/docs/CHANGES [2] http://www.horde.org/apps/imp/docs/RELEASE_NOTES [3] http://secunia.com/advisories/47580 [4] https://bugs.gentoo.org/show_bug.cgi?id=399563 Upstream patches: [5] https://github.com/horde/horde/commit/41136ea893b3d5a84c6228a552f8e211c90f58de (multiple XSS flaws) [6] https://github.com/horde/horde/commit/208eae43c95136a67104f760027a8892a22b6e25 (XSS in email validation) Could you allocate CVE ids for these? (two should be enough, one for the multiple XSS flaws patch and one for XSS in email validation patch) Thank you && Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team
Current thread:
- CVE Request -- Horde IMP -- Multiple XSS flaws fixed in v5.0.18 Jan Lieskovsky (Jan 21)
- Re: CVE Request -- Horde IMP -- Multiple XSS flaws fixed in v5.0.18 Kurt Seifried (Jan 21)
- Re: CVE Request -- Horde IMP -- Multiple XSS flaws fixed in v5.0.18 Steven M. Christey (Jan 21)
- Re: CVE Request -- Horde IMP -- Multiple XSS flaws fixed in v5.0.18 Kurt Seifried (Jan 21)