Re: [SM-USERS] [SquirrelMail Security Advisory] Cross Site Scripting in encoded text

2004-11-13 Thread Jonathan Angliss
Hello Norrin, On Friday, November 12, 2004, Norrin Radd wrote... > Below is all I got, should I have gotten more output? Anyway of > verifying that the patch installed correctly? > Thanks, > [EMAIL PROTECTED] squirrelmail]# patch -p0 < sm143a-xss.diff > patching file functions/mime.php > [EMA

Re: [SM-USERS] [SquirrelMail Security Advisory] Cross Site Scripting in encoded text

2004-11-12 Thread Norrin Radd
Below is all I got, should I have gotten more output?  Anyway of verifying that the patch installed correctly?   Thanks,   [EMAIL PROTECTED] squirrelmail]# patch -p0 < sm143a-xss.diffpatching file functions/mime.php[EMAIL PROTECTED] squirrelmail]#Jonathan Angliss <[EMAIL PROTECTED]> wrote: Squirrel

Re: [SM-USERS] [SquirrelMail Security Advisory] Cross Site Scripting in encoded text

2004-11-11 Thread Tomas Kuliavas
> > Ebbe Hjorth wrote: > >> What about us that dont have access to run the .diff file? > > You can get a cvs snapshot of the whole tarball (and just extract > functions/mime.php if you just want the patched file) from the downloads > page Please don't do that. Don't mix files from current 1.4.4cv

Re: [SM-USERS] [SquirrelMail Security Advisory] Cross Site Scripting in encoded text

2004-11-11 Thread p dont think
please respond on list. Okay, what is a CVS snapshot to be exact? http://www.gnu.org/software/cvs/ CVS is software that manages our development work on the project. getting a snapshot gets you the very latest code with all the most recent fixes and enhancements. And why isnt it fixed in 1.4.3a?

Re: [SM-USERS] [SquirrelMail Security Advisory] Cross Site Scripting in encoded text

2004-11-11 Thread p dont think
So you are saying that i just have to download the newest SM from the download page? Yes. But DO NOT get 1.4.3a. You *must* download a CVS snapshot (scroll to the very bottom) - Paul Keep up the good work - Ebbe, Denmark Ebbe Hjorth wrote: What about us that dont have access to run the .dif

Re: [SM-USERS] [SquirrelMail Security Advisory] Cross Site Scripting in encoded text

2004-11-11 Thread p dont think
Ebbe Hjorth wrote: What about us that dont have access to run the .diff file? You can get a cvs snapshot of the whole tarball (and just extract functions/mime.php if you just want the patched file) from the downloads page or you can open the diff file and manually delete and insert the lines as

Re: [SM-USERS] [SquirrelMail Security Advisory] Cross Site Scripting in encoded text

2004-11-10 Thread Ebbe Hjorth
What about us that dont have access to run the .diff file? Best regards Ebbe, Denmark > SquirrelMail Security Notice > > > About > - > SquirrelMail is a standards-based webmail package written in PHP4. It > includes built-in pure PHP support for the IMAP and SMTP

[SM-USERS] [SquirrelMail Security Advisory] Cross Site Scripting in encoded text

2004-11-10 Thread Jonathan Angliss
SquirrelMail Security Notice About - SquirrelMail is a standards-based webmail package written in PHP4. It includes built-in pure PHP support for the IMAP and SMTP protocols, and all pages render in pure HTML 4.0 (with no JavaScript required) for maximum compatibil

[SM-USERS] [SquirrelMail Security Advisory] Cross Site Scripting in encoded text

2004-11-10 Thread Jonathan Angliss
SquirrelMail Security Notice About - SquirrelMail is a standards-based webmail package written in PHP4. It includes built-in pure PHP support for the IMAP and SMTP protocols, and all pages render in pure HTML 4.0 (with no JavaScript required) for maximum compatibil