Mhonarc Update for Debian
Posted on: 11/20/2002 01:29 PM

A new security update for Debian GNU/Linux is available

Steven Christey discovered a cross site scripting vulnerability in mhonarc, a mail to HTML converter. Carefully crafted message headers can introduce cross site scripting when mhonarc is configured to display all headers lines on the web. However, it is often useful to restrict the displayed header lines to To, From and Subject, in which case the vulnerability cannot be exploited.

This problem has been fixed in version 2.5.2-1.2 for the current stable distribution (woody), in version 2.4.4-1.2 for the old stable distribution (potato) and in version 2.5.13-1 for the unstable distribution (sid).


Read more


Printed from Linux Compatible (http://www.linuxcompatible.org/news/story/mhonarc_update_for_debian.html)