Bug#685475: roundcube: CVE-2012-3508

2012-08-26 Thread Moritz Muehlenhoff
On Sun, Aug 26, 2012 at 02:34:30PM +0200, Vincent Bernat wrote: > ❦ 21 août 2012 07:51 CEST, Moritz Muehlenhoff  : > Hi Moritz! > > The version currently in stable (0.3) is not affected by either of the > bugs (I was unable to reproduce them). The version in testing is > affected by the later bug

Bug#685475: roundcube: CVE-2012-3508

2012-08-26 Thread Vincent Bernat
❦ 21 août 2012 07:51 CEST, Moritz Muehlenhoff  : > Package: roundcube > Severity: grave > Tags: security > Justification: user security hole > > This was reported on the oss-sec mailing list: > > Cheers, > Moritz > -- > >> 2, Issue 2a: Description: Stored XSS in e-mail body. Ticket: >> ht

Bug#685475: roundcube: CVE-2012-3508

2012-08-20 Thread Moritz Muehlenhoff
Package: roundcube Severity: grave Tags: security Justification: user security hole This was reported on the oss-sec mailing list: Cheers, Moritz -- > 2, Issue 2a: Description: Stored XSS in e-mail body. Ticket: > http://trac.roundcube.net/ticket/1488613 Upstream patch: > https://github.