Horde framework upstream versions 3.2.3 and 3.3.1 improve XSS filter to catch one reportedly MSIE specific XSS issue: * Added another check to the XSS filter (only IE is vulnerable). Release announcements: http://lists.horde.org/archives/announce/2008/000462.html (3.2.3) http://lists.horde.org/archives/announce/2008/000464.html (3.3.1) Patch: http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.413.2.1&r2=1.515.2.413.2.3&ty=h http://cvs.horde.org/diff.php/framework/Text_Filter/Filter/xss.php?r1=1.17&r2=1.18 Test cases: http://cvs.horde.org/diff.php/framework/Text_Filter/tests/xss.phpt?r1=1.1.2.3&r2=1.1.2.4 http://cvs.horde.org/framework/Text_Filter/tests/xss100.html xss100.html is: <img src='blank.jpg'style='width:expression(alert("xssed"))'>
Bump to upstream 3.2.3 should also fix other two horde XSS issue not yet fixed in Fedora: bug #461886 and bug #461886. All changes between 3.2.1 and 3.2.3 seem to be related to XSS fixes.
CVE-2008-5917: Cross-site scripting (XSS) vulnerability in the XSS filter (framework/Text_Filter/Filter/xss.php) in Horde Application Framework 3.2.2 and 3.3, when Internet Explorer is being used, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to style attributes.
horde-3.3.6-1.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/horde-3.3.6-1.fc11
horde-3.3.6-1.fc12 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/horde-3.3.6-1.fc12
horde-3.3.6-1.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/horde-3.3.6-1.fc13
horde-3.3.6-1.el5 has been submitted as an update for Fedora EPEL 5. http://admin.fedoraproject.org/updates/horde-3.3.6-1.el5
horde-3.3.6-1.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.
horde-3.3.6-1.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report.
horde-3.3.6-1.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report.
horde-3.3.6-1.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.