Bug#607693: mhonarc: cross-site scripting when converting HTML mails

2011-01-01 Thread Jeff Breidenbach
After extensive discussion, upstream is preparing a new release of mhonarc (the security and related bug fixes are more extensive than the patch supplied to Debian). I prefer to ship the new release as the security update, rather than attempt a backport. Happy to discuss if security team has any

Bug#607693: mhonarc: cross-site scripting when converting HTML mails

2010-12-30 Thread Jeff Breidenbach
Based on discussion with Earl so far, I think the correct fix is disabling HTML mail support by default.

Bug#607693: mhonarc: cross-site scripting when converting HTML mails

2010-12-20 Thread non customers
Subject: mhonarc: cross-site scripting when converting HTML mails Package: mhonarc Version: 2.6.16-1 Severity: important Tags: security MHonArc has a cross-site scripting (XSS) security issue when converting HTML mails with malformed HTML tags of the form scrbodyipt: $ mhonarc elsatest.mbox This