You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

66 lines
2.2 KiB

<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE glsa SYSTEM "http://www.gentoo.org/dtd/glsa.dtd">
<glsa id="200408-07">
<title>Horde-IMP: Input validation vulnerability for Internet Explorer users</title>
<synopsis>
An input validation vulnerability has been discovered in Horde-IMP. This
only affects users of Internet Explorer.
</synopsis>
<product type="ebuild">horde-imp</product>
<announced>August 10, 2004</announced>
<revised>May 22, 2006: 02</revised>
<bug>59336</bug>
<access>remote</access>
<affected>
<package name="www-apps/horde-imp" auto="yes" arch="*">
<unaffected range="ge">3.2.5</unaffected>
<vulnerable range="le">3.2.4</vulnerable>
</package>
</affected>
<background>
<p>
Horde-IMP is the Internet Messaging Program. It is written in PHP and
provides webmail access to IMAP and POP3 accounts.
</p>
</background>
<description>
<p>
Horde-IMP fails to properly sanitize email messages that contain
malicious HTML or script code so that it is not safe for users of
Internet Explorer when using the inline MIME viewer for HTML messages.
</p>
</description>
<impact type="normal">
<p>
By enticing a user to read a specially crafted e-mail, an attacker can
execute arbitrary scripts running in the context of the victim's
browser. This could lead to a compromise of the user's webmail account,
cookie theft, etc.
</p>
</impact>
<workaround>
<p>
Do not use Internet Explorer to access Horde-IMP.
</p>
</workaround>
<resolution>
<p>
All Horde-IMP users should upgrade to the latest stable version:
</p>
<code>
# emerge sync
# emerge -pv &quot;&gt;=www-apps/horde-imp-3.2.5&quot;
# emerge &quot;&gt;=www-apps/horde-imp-3.2.5&quot;</code>
</resolution>
<references>
<uri link="http://cvs.horde.org/diff.php/imp/docs/CHANGES?r1=1.389.2.106&amp;r2=1.389.2.109&amp;ty=h">Horde-IMP Changelog</uri>
<uri link="http://secunia.com/advisories/12202/">Secunia Advisory SA12202</uri>
<uri link="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1443">CVE-2004-1443</uri>
</references>
<metadata tag="submitter" timestamp="Sun, 8 Aug 2004 18:55:04 +0000">
jaervosz
</metadata>
</glsa>