Upstream information
Description
Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004, allows remote attackers to execute arbitrary web script or HTML.NVD CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entries: 64182, 74717, 96563 SUSE Security Advisories:- SUSE-SR:2004:004, published Thursday, Dec 16th 2004 12:00 MEST
- SUSE-SR:2004:005, published Tuesday, Dec 21th 2004 15:00 MEST
- SUSE-SR:2005:002, published Wednesday, Jan 26th 2005 17:00 MEST
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SuSE Linux 9.0 for AMD64 SuSE Linux 9.0 for IA32 |
| |
| SUSE LINUX 9.1 for IA32 SUSE LINUX 9.1 for x86-64 |
| |
| SUSE LINUX 9.2 |
| |
| SUSE LINUX 9.3 |
|
