Bug#607693: mhonarc: cross-site scripting when converting HTML mails

2011-01-01 Thread Jeff Breidenbach
After extensive discussion, upstream is preparing a new release of mhonarc (the security and related bug fixes are more extensive than the patch supplied to Debian). I prefer to ship the new release as the security update, rather than attempt a backport. Happy to discuss if security team has any co

Bug#607693: mhonarc: cross-site scripting when converting HTML mails

2010-12-30 Thread Jeff Breidenbach
Based on discussion with Earl so far, I think the correct fix is disabling HTML mail support by default.

Processed: Bug #607693: mhonarc: cross-site scripting when converting HTML mails: add tag patch

2010-12-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 607693 +patch Bug #607693 [mhonarc] mhonarc: cross-site scripting when converting HTML mails Added tag(s) patch. > thanks Stopping processing here. Please contact me if you need assistance. -- 607693: http://bugs.debian.org/cgi-bin/bugreport