Your message dated Tue, 3 Apr 2007 08:38:22 +0200
with message-id <[EMAIL PROTECTED]>
and subject line [pkg-horde] Bug#417524: imp4 4.1.4 contains securityfixes
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: imp4
Version: 4.1.3-4
Severity: grave
Tags: security
Justification: user security hole

http://lists.horde.org/archives/announce/2007/000316.html mentions a new 
version of horde, most important are:
    * Fixed XSS vulnerabilities in the search screen and thread view.

I would like to see a fixed version of imp4 :P

-- System Information:
Debian Release: 4.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.20.1
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)

Versions of packages imp4 depends on:
ii  horde3                   3.1.3-4         horde web application framework
ii  php-mail-mime            1.3.1-1.1       PHP PEAR module for creating and d
ii  php4-imap                6:4.4.4-8+etch1 IMAP module for php4
ii  php5-imap                5.2.0-8+etch1   IMAP module for php5

Versions of packages imp4 recommends:
ii  locales                     2.3.6.ds1-13 GNU C Library: National Language (

-- no debconf information


--- End Message ---
--- Begin Message ---
Hi

On Tue, Apr 03, 2007 at 12:48:41AM +0200, [EMAIL PROTECTED] wrote:
> Package: imp4
> Version: 4.1.3-4
> Severity: grave
> Tags: security
> Justification: user security hole
> 
> http://lists.horde.org/archives/announce/2007/000316.html mentions a new 
> version of horde, most important are:
>     * Fixed XSS vulnerabilities in the search screen and thread view.
> 
> I would like to see a fixed version of imp4 :P

Yes I know and that fix is actually part of the 4.1.3-4 package. If you read 
the changelog
you will notice that it is backported.

Thanks for your help anyway.

Regards,

// Ola

> -- System Information:
> Debian Release: 4.0
>   APT prefers testing
>   APT policy: (500, 'testing')
> Architecture: amd64 (x86_64)
> Shell:  /bin/sh linked to /bin/bash
> Kernel: Linux 2.6.20.1
> Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
> 
> Versions of packages imp4 depends on:
> ii  horde3                   3.1.3-4         horde web application framework
> ii  php-mail-mime            1.3.1-1.1       PHP PEAR module for creating and 
> d
> ii  php4-imap                6:4.4.4-8+etch1 IMAP module for php4
> ii  php5-imap                5.2.0-8+etch1   IMAP module for php5
> 
> Versions of packages imp4 recommends:
> ii  locales                     2.3.6.ds1-13 GNU C Library: National Language 
> (
> 
> -- no debconf information
> 
> 
> _______________________________________________
> pkg-horde-hackers mailing list
> [EMAIL PROTECTED]
> http://lists.alioth.debian.org/mailman/listinfo/pkg-horde-hackers
> 

-- 
 --------------------- Ola Lundqvist ---------------------------
/  [EMAIL PROTECTED]                     Annebergsslingan 37      \
|  [EMAIL PROTECTED]                     654 65 KARLSTAD          |
|  +46 (0)54-10 14 30                  +46 (0)70-332 1551       |
|  http://opalsys.net/                 UIN/icq: 4912500         |
\  gpg/f.p.: 7090 A92B 18FE 7994 0C36  4FE4 18A1 B1CF 0FE5 3DD9 /
 ---------------------------------------------------------------

--- End Message ---

Reply via email to