Accepted mhonarc 2.5.2-1.2 (all source)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Thu, 14 Nov 2002 21:36:11 +0100
Source: mhonarc
Binary: mhonarc
Architecture: source all
Version: 2.5.2-1.2
Distribution: stable-security
Urgency: high
Maintainer: Jeff Breidenbach <jab@debian.org>
Changed-By: Martin Schulze <joey@infodrom.org>
Description:
mhonarc - Mail to HTML converter
Changes:
mhonarc (2.5.2-1.2) stable-security; urgency=high
.
* Non-maintainer upload by the Security Team
* Make sure to htmlize name parameter to avoid any potential
XSS. (upstream)
* XSS vulnerability with message header fields fixed: Message header
field names were not escaped during conversion to HTML. Hence,
an attacker could including scripting markup in the message
header. (upstream)
Files:
8f9fed3cf8291da812c8f286c235aecb 560 mail optional mhonarc_2.5.2-1.2.dsc
a2883f16cba2cd5e71bbfc2afa1af67b 4737 mail optional mhonarc_2.5.2-1.2.diff.gz
84fe390991cf60c2ccea131a681a6288 573016 mail optional mhonarc_2.5.2-1.2_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)
iD8DBQE91A7KW5ql+IAeqTIRAs0XAKCnLIKBs35HTstJIW00vXDtQdNDRQCgqSZP
x87wPH70TTkFU9FVbzZQd6c=
=h8eS
-----END PGP SIGNATURE-----
Accepted:
mhonarc_2.5.2-1.2.diff.gz
to pool/main/m/mhonarc/mhonarc_2.5.2-1.2.diff.gz
mhonarc_2.5.2-1.2.dsc
to pool/main/m/mhonarc/mhonarc_2.5.2-1.2.dsc
mhonarc_2.5.2-1.2_all.deb
to pool/main/m/mhonarc/mhonarc_2.5.2-1.2_all.deb
Reply to: