Bug 139741 - CAN-2004-1036 Cross Site Scripting in encoded text
Summary: CAN-2004-1036 Cross Site Scripting in encoded text
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: squirrelmail
Version: 3
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Warren Togami
QA Contact:
URL:
Whiteboard: impact=moderate,public=20041110
Keywords: Security
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2004-11-17 20:10 UTC by Josh Bressers
Modified: 2007-11-30 22:10 UTC (History)
2 users (show)

(edit)
Clone Of:
(edit)
Last Closed: 2004-12-03 09:25:46 UTC


Attachments (Terms of Use)

Description Josh Bressers 2004-11-17 20:10:37 UTC
There is a cross site scripting issue in the decoding of encoded text
in certain headers. SquirrelMail correctly decodes the specially
crafted header, but doesn't sanitize the decoded strings.

This issue should also affect FC2.

Comment 1 Josh Bressers 2004-11-17 20:12:07 UTC
Attachment 106907 [details] contains the fix for this issue.

Comment 2 Warren Togami 2004-12-03 09:25:46 UTC
Updates for FC2 and FC3 have been issued.


Note You need to log in before you can comment on or make changes to this bug.