Red Hat Bugzilla – Bug 139739
CAN-2004-1036 Cross Site Scripting in encoded text
Last modified: 2007-11-30 17:07:05 EST
There is a cross site scripting issue in the decoding of encoded text in certain headers. SquirrelMail correctly decodes the specially crafted header, but doesn't sanitize the decoded strings.
We'll want to make sure that this fix makes it into RHEL4 as well.
Created attachment 106907 [details] Upstream patch for this issue.
dist-3.0E-errata-candidate squirrelmail-1.4.3a-7.EL3 is ready. Do you want to handle pushing? CHANGLEOG since previous RHEL3 errata: ====================================== - sync with RHEL4 1.4.3a-7 except dovecot default config removed - CAN-2004-1036 Cross Site Scripting in encoded text - #112769 updated splash screens - HIGASHIYAMA Masato's patch to improve Japanese support (coordinated by Scott A. Hughes). - real 1.4.3a tarball - #125638 config_local.php and default_pref in /etc/squirrelmail/ to match upstream RPM. This should allow smoother drop-in replacements and upgrades.
Will be RHSA-2004:654
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2004-654.html