-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 15 May 2007 18:49:35 -0600 Source: squirrelmail Binary: squirrelmail Architecture: i386_translations all Version: 2:1.4.8-1ubuntu0.1 Distribution: edgy-security Urgency: low Maintainer: Ubuntu/i386 Build Daemon Changed-By: Leonel Nunez Description: squirrelmail - Webmail for nuts Changes: squirrelmail (2:1.4.8-1ubuntu0.1) edgy-security; urgency=low . * SECURITY UPDATE: XSS and CSRF in various areas * src/compose.php, src/right_main.php, src/login.php, src/mailto.php, src/redirect.php, src/webmail.php, src/mime.php: back-ported fixes for XSS in compose, draft and HTML mail. (CVE-2006-6142) http://www.squirrelmail.org/security/issue/2006-12-02 * fuctions/mime.php, src/compose.php, src/view_text.php: back-ported fixes for XSS in HTML filter (CVE-2007-1262) http://www.squirrelmail.org/security/issue/2007-05-09 Files: c42daec5747fae9bda12c4484568cabf 583404 web optional squirrelmail_1.4.8-1ubuntu0.1_all.deb fbbfbb5e565575d5563ba65fb386b865 30142 raw-translations - squirrelmail_1.4.8-1ubuntu0.1_i386_translations.tar.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFGSoWw0N0xjzyQZEIRAg4nAJ0aMn+5DB38OgaqGJmrnNlRlwdnHgCePSIo i1eoqeOBfwTkaiQ1NzDLR40= =gUEp -----END PGP SIGNATURE-----