[pkg-horde] Bug#461131: Bug#461131: CVE-2007-6018: horde3 privilege escalation

Nico Golde nion at debian.org
Sun Jan 20 14:31:52 UTC 2008


Hi Gregory,
* Gregory Colpart <reg at evolix.fr> [2008-01-20 03:12]:
> On Sun, Jan 20, 2008 at 01:30:37AM +0100, Nico Golde wrote:
> > are you also going to fix imp4?
> 
> CVE-2007-6018 doesn't affect directly package imp4.
> Security problems are in 'lib/Horde/Text/Filter/xss.php'
> file which is only part of horde3 package. For more information,
> you can see my patch for horde3/stable-security:
> http://arch.debian.org/cgi-bin/archzoom.cgi/pkg-horde-hackers@lists.alioth.debian.org--2006/horde--etch--3--patch-4/lib/Horde/Text/Filter/xss.php.diff?diff

Thanks alot. I marked this in the security tracker.
Kind regards
Nico
-- 
Nico Golde - http://www.ngolde.de - nion at jabber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.alioth.debian.org/pipermail/pkg-horde-hackers/attachments/20080120/cb82ecfa/attachment.pgp 


More information about the pkg-horde-hackers mailing list