Bug 160241
Summary: | CAN-2005-1769 Multiple XSS issues in squirrelmail | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 4 | Reporter: | Josh Bressers <bressers> | ||||||
Component: | squirrelmail | Assignee: | Warren Togami <wtogami> | ||||||
Status: | CLOSED ERRATA | QA Contact: | |||||||
Severity: | medium | Docs Contact: | |||||||
Priority: | medium | ||||||||
Version: | 4.0 | CC: | jhughes, jnovy, security-response-team | ||||||
Target Milestone: | --- | Keywords: | Security | ||||||
Target Release: | --- | ||||||||
Hardware: | All | ||||||||
OS: | Linux | ||||||||
Whiteboard: | public=20050615,impact=moderate,source=vendor-sec,reported=20050612 | ||||||||
Fixed In Version: | RHSA-2005-595 | Doc Type: | Bug Fix | ||||||
Doc Text: | Story Points: | --- | |||||||
Clone Of: | Environment: | ||||||||
Last Closed: | 2005-08-03 14:16:04 UTC | Type: | --- | ||||||
Regression: | --- | Mount Type: | --- | ||||||
Documentation: | --- | CRM: | |||||||
Verified Versions: | Category: | --- | |||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||
Embargoed: | |||||||||
Attachments: |
|
Description
Josh Bressers
2005-06-13 19:20:59 UTC
This issue should also affect RHEL3 Created attachment 115373 [details]
Current upstream patch
Created attachment 115434 [details]
Latest upstream patch
removing embargo An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2005-595.html There is a problem with the patch file squirrelmail-1.4.3a-CAN-2005-1769.patch the line $abook-error = htmlspecialchars($abook_error); should be $abook->error = htmlspecialchars($abook_error); Jindrich, If you can roll up some new packages without the typo ASAP. It seems this bug breaks all addressbooks in squirrelmail. This type came from upstream, they fixed it without telling anyone. Josh, packages with the fixed patch are now added. *** Bug 165094 has been marked as a duplicate of this bug. *** |