Bug 239649

Summary: CVE-2007-1262 XSS through HTML message in squirrelmail
Product: Red Hat Enterprise Linux 5 Reporter: Mark J. Cox <mjc>
Component: squirrelmailAssignee: Martin Bacovsky <mbacovsk>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 5.0CC: eric.eisenhart
Target Milestone: ---Keywords: Security, ZStream
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://www.squirrelmail.org/security/issue/2007-05-09
Whiteboard: impact=moderate,source=internet,public=20070509,reported=20070509
Fixed In Version: 5.1.0 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-08-13 16:13:14 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 239648    
Bug Blocks: 239647    

Description Mark J. Cox 2007-05-10 09:32:51 UTC
Tracking bug for this issue affecting 5.1; see "blocks" bug for details.

Comment 2 Martin Bacovsky 2007-05-10 16:34:23 UTC
This issue should be fixed in squirrelmail-1.4.8-4.1.el5.