[SECURITY] [DSA 1470-1] New horde3 packages fix denial of service

Debian Security Advisory DSA-1470-1                  security@debian.org
http://www.debian.org/security/                       Moritz Muehlenhoff
January 20, 2008                      http://www.debian.org/security/faq
Package        : horde3
Vulnerability  : missing input sanitising
Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2007-6018

Ulf Harnhammer discovered that the HTML filter of the Horde web
application framework performed insufficient input sanitising, which
may lead to the deletion of emails if a user is tricked into viewing
a malformed email inside the Imp client.

This update also provides backported bugfixes to the cross-site 
scripting filter and the user management API from the latest Horde
release 3.1.6.

For the stable distribution (etch), this problem has been fixed in
version 3.1.3-4etch2.

The old stable distribution (sarge) is not affected. An update to
Etch is recommended, though.

We recommend that you upgrade your horde3 package.

