[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-16 Thread leonel
this is for dapper ** Attachment added: dapper.debdiff http://librarian.launchpad.net/7677480/dapper.debdiff -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-16 Thread Kees Cook
Very cool. Thanks for getting this packaged up and tested. I will have it published as soon as the build is finished. Thank you again! ** Changed in: squirrelmail (Ubuntu Dapper) Status: In Progress = Fix Released -- Cross site scripting in HTML filter

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-15 Thread Scott Kitterman
** Changed in: squirrelmail (Ubuntu Dapper) Importance: Undecided = High Assignee: (unassigned) = leonel Status: Unconfirmed = In Progress ** Changed in: squirrelmail (Ubuntu Edgy) Importance: Undecided = High Assignee: (unassigned) = leonel Status: Unconfirmed = In

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-15 Thread leonel
this is for edgy pbuilder was successful and patch applied installed and deb tested ** Attachment added: debdiff for edgy http://librarian.launchpad.net/7662793/various-xss.debdiff -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-15 Thread Kees Cook
Your debdiff looks good, and built fine for me. I adjusted the changelog a little, and I've sponsored the upload. :) I should have it published as soon as it's done building. ** Changed in: squirrelmail (Ubuntu Edgy) Status: In Progress = Fix Released -- Cross site scripting in HTML

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-14 Thread Kees Cook
I am confused by the attachments. :) Which is the correct version? regression-fix or html-filter ? -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. --

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-14 Thread Kees Cook
Debian's version (2:1.4.10a-1) has this fixed now. ** Changed in: squirrelmail (Ubuntu Gutsy) Status: Confirmed = Fix Released -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug notification because you are a member of Ubuntu Bugs, which

Re: [Bug 113725] Re: Cross site scripting in HTML filter

2007-05-14 Thread Scott Kitterman
It's the last attachment. I can't tell you which one it is because the new LP hmi doesn't work on my Treo. -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-14 Thread leonel
It's the last attachment it has the html-filter patch and the regression patch the first 2 attachments where done by editing debian/rules the last attachment does not have debian/rules edited -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-11 Thread leonel
** Attachment added: html-filter-fix.debdiff http://librarian.launchpad.net/7608186/html-filter-fix.debdiff -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-11 Thread Daniel T Chen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Fri, 11 May 2007 18:39:34 -0600 Source: squirrelmail Binary: squirrelmail Architecture: source Version: 2:1.4.9a-1ubuntu0.1 Distribution: feisty-security Urgency: low Maintainer: Jeroen van Wolffelaar [EMAIL PROTECTED] Changed-By:

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-10 Thread Kees Cook
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2007-1262 -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-bugs mailing list

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-10 Thread Scott Kitterman
** Changed in: squirrelmail (Ubuntu Feisty) Importance: Undecided = High Status: Unconfirmed = Confirmed ** Changed in: squirrelmail (Ubuntu Gutsy) Importance: Undecided = High Status: Unconfirmed = Confirmed -- Cross site scripting in HTML filter

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-10 Thread Scott Kitterman
Note that squirrelmail issued an updated patch to deal with a regression, so we should understand that before publishing the fix. -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug notification because you are a member of Ubuntu Bugs, which is the

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-10 Thread leonel
pbuilder was succeful and the regression patch applied ** Attachment added: regression-fix.debdiff http://librarian.launchpad.net/7599502/regression-fix.debdiff -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug notification because you are a

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-10 Thread Scott Kitterman
Looks good to me. Confirmed the patch has been modified successfully for the regression fix. -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. --

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-09 Thread leonel
** Visibility changed to: Public -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-09 Thread leonel
upstream advisory http://www.squirrelmail.org/security/issue/2007-05-09 -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-bugs mailing list

[Bug 113725] Re: Cross site scripting in HTML filter

2007-05-09 Thread Scott Kitterman
For Gutsy, we can probably just wait for 1.4.10 to get packaged an sync from Debian. -- Cross site scripting in HTML filter https://bugs.launchpad.net/bugs/113725 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-bugs