[imp] Re: [announce] IMP 3.2.6 (final)
Jan Schneider
jan at horde.org
Mon Oct 4 08:22:48 PDT 2004
Zitat von Federico Petronio <petrus at activesec.biz>:
> Jan Schneider wrote:
>
>> The Horde Team is pleased to announce the official release of the
>> IMP Webmail
>> Client version 3.2.6.
>> Changes in this release:
>> - SECURITY: Removed tags with -moz-binding: styles in the HTML
>> MIME viewer.
>> - SECURITY: Removed scripts from <base> tags in the HTML MIME viewer.
>> - SECURITY: Removed scripts from obfuscated "on..." attributes
>> in the HTML
>> MIME viewer.
>
> Hello... I will be grateful if you could post a patch to fix the
> security issues without updating the release. I currently run Horde
> 3.2.3 and IMP 3.2.3 with security patches up to 3.2.5.
Just grab the latest imp/lib/MIME/Viewer/html.php of the RELENG_3 branch
from CVS.
Jan.
--
Do you need professional PHP or Horde consulting?
http://horde.org/consulting/
More information about the imp
mailing list