Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 139741 - CAN-2004-1036 Cross Site Scripting in encoded text
CAN-2004-1036 Cross Site Scripting in encoded text
Product: Fedora
Classification: Fedora
Component: squirrelmail (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Warren Togami
: Security
Depends On:
  Show dependency treegraph
Reported: 2004-11-17 15:10 EST by Josh Bressers
Modified: 2007-11-30 17:10 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2004-12-03 04:25:46 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Josh Bressers 2004-11-17 15:10:37 EST
There is a cross site scripting issue in the decoding of encoded text
in certain headers. SquirrelMail correctly decodes the specially
crafted header, but doesn't sanitize the decoded strings.

This issue should also affect FC2.
Comment 1 Josh Bressers 2004-11-17 15:12:07 EST
Attachment 106907 [details] contains the fix for this issue.
Comment 2 Warren Togami 2004-12-03 04:25:46 EST
Updates for FC2 and FC3 have been issued.

Note You need to log in before you can comment on or make changes to this bug.