Bug#461131: [pkg-horde] Bug#461131: CVE-2007-6018: horde3 privilege escalation

2008-01-20 Thread Nico Golde
Hi Gregory, * Gregory Colpart [EMAIL PROTECTED] [2008-01-20 03:12]: On Sun, Jan 20, 2008 at 01:30:37AM +0100, Nico Golde wrote: are you also going to fix imp4? CVE-2007-6018 doesn't affect directly package imp4. Security problems are in 'lib/Horde/Text/Filter/xss.php' file which is only

Bug#461131: [pkg-horde] Bug#461131: CVE-2007-6018: horde3 privilege escalation

2008-01-19 Thread Gregory Colpart
Hi, On Sun, Jan 20, 2008 at 01:30:37AM +0100, Nico Golde wrote: are you also going to fix imp4? CVE-2007-6018 doesn't affect directly package imp4. Security problems are in 'lib/Horde/Text/Filter/xss.php' file which is only part of horde3 package. For more information, you can see my patch for

Bug#461131: [pkg-horde] Bug#461131: CVE-2007-6018: horde3 privilege escalation

2008-01-17 Thread Ola Lundqvist
Hi Stefan Thanks a lot for the report! I saw the announce yesterday, but I have not had the time to correct it at this very moment. Best regards, // Ola On Wed, Jan 16, 2008 at 09:19:48PM +0100, Stefan Fritsch wrote: Package: horde3 Version: 3.1.3-4 Severity: important Tags: security A