Bug#342654: CVE-2005-4080: Bypass of input sanitising with Internet Explorer

2005-12-10 Thread Ola Lundqvist
Hi On Fri, Dec 09, 2005 at 11:00:57PM +0100, Florian Weimer wrote: > * Ola Lundqvist: > > > As i understand this article at gmane.org this is a IE bug. Fixing this > > in horde do not give much effect as it is just as simple to trigger this > > bug in any html page anywhere else. > > But these H

Bug#342654: CVE-2005-4080: Bypass of input sanitising with Internet Explorer

2005-12-09 Thread Florian Weimer
* Ola Lundqvist: > As i understand this article at gmane.org this is a IE bug. Fixing this > in horde do not give much effect as it is just as simple to trigger this > bug in any html page anywhere else. But these HTML pages cannot retrieve session authentication information from IMP. In the end

Bug#342654: CVE-2005-4080: Bypass of input sanitising with Internet Explorer

2005-12-09 Thread Ola Lundqvist
Severity 342654 wishlist thanks Hi I do not fully understand this. As i understand this article at gmane.org this is a IE bug. Fixing this in horde do not give much effect as it is just as simple to trigger this bug in any html page anywhere else. Horde/imp could of course fix this by filter it

Bug#342654: CVE-2005-4080: Bypass of input sanitising with Internet Explorer

2005-12-09 Thread Moritz Muehlenhoff
Package: imp4 Severity: important Tags: security It has been discovered that an Internet Explorer specific interpretation flaw can be abused to bypass the sanitising features of IMP. Please see http://article.gmane.org/gmane.comp.security.bugtraq/20693 for more information. In a followup on of th