OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Albert Cervera Areny (albertca_at_jazzfree.com)
Date: Fri Sep 20 2002 - 08:47:41 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Debian testing and unstable use it too..

    ---------- Missatge transmès ----------

    Subject: Re: Squirrel Mail 1.2.7 XSS Exploit
    Date: Thu, 19 Sep 2002 16:51:09 -0500 (CDT)
    From: "Jason Munro" <jasonstdbev.com>
    To: <bugtraqsecurityfocus.com>

    DarC KonQuesT said:
    > ****Sorry if you receive two of these.****
    >
    > DarC KonQuesT XSS Release-
    >
    > Product: Squirrel Mail 1.2.7 - released June 21, 2002 (tested, others
    > possibly vulnerable)
    > Vendor: Squirrel Mail - Web: www.squirrelmail.org
    > Problem: Cross Site Scripting
    > Severity: Moderate
    > Operating System(s): Tested against Red Hat 7.3, all others vulnerable
    > if they are using this version of Squirrel.

    Mr KonQuesT,
      All the listed exploits have been fixed in the recently released 1.2.8
    version of SquirrelMail. These fixes have also been applied to the
    current development and stable CVS, 1.3.2 and 1.2.9 respectively.

     \___ Jason Munro
      \___ AIM:jmunr0
       \__ jasonstdbev.com
        \__ http://www.sunflower.com/~jmunro/

    -------------------------------------------------------

    -- 
    To UNSUBSCRIBE, email to debian-security-requestlists.debian.org
    with a subject of "unsubscribe". Trouble? Contact listmasterlists.debian.org