2009/12/10 Roberto Suggi Liverani :
Hi Alan,
Sorry for the delay, very busy days here...
The vulnerability was originally reported in the Sage bugzilla
mailing-list and here you can find the link:
https://www.mozdev.org/bugs/show_bug.cgi?id=20610
and here is the security report detailing the
diff -uNr sage.orig/content/createhtml.js sage/content/createhtml.js
--- sage.orig/content/createhtml.js 2009-07-02 15:19:32.0 +0100
+++ sage/content/createhtml.js 2009-12-06 18:00:05.0 +
@@ -242,7 +242,7 @@
this.simpleHtmlParser.parse(item.getContent());
ds = this
2 matches
Mail list logo