Re: [SM-USERS] Vuln Linux vulnerability and SM 1.4.3a

2004-12-06 Thread Tony Earnshaw
man, 06.12.2004 kl. 12.07 skrev Tomas Kuliavas: > > Could any of the developers comment on the following urls, reported it > > Saturday's vuln, please? > > These announcement are made by third party squirrelmail packagers. They > provide link to announcement made by SquirrelMail developers. Packa

Re: [SM-USERS] Vuln Linux vulnerability and SM 1.4.3a

2004-12-06 Thread Tomas Kuliavas
> Could any of the developers comment on the following urls, reported it > Saturday's vuln, please? These announcement are made by third party squirrelmail packagers. They provide link to announcement made by SquirrelMail developers. Packagers inform public about exploit fixes in their packages. S

[SM-USERS] Vuln Linux vulnerability and SM 1.4.3a

2004-12-06 Thread Tony Earnshaw
Could any of the developers comment on the following urls, reported it Saturday's vuln, please? _ "Joost Pol noticed[2] that SquirrelMail is prone to a cross site scripting issue in the decoding of encoded text in certain headers. SquirrelMail correctly decodes