-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Thu, 14 Nov 2002 21:36:11 +0100 Source: mhonarc Binary: mhonarc Architecture: source all Version: 2.5.2-1.2 Distribution: stable-security Urgency: high Maintainer: Jeff Breidenbach <[EMAIL PROTECTED]> Changed-By: Martin Schulze <[EMAIL PROTECTED]> Description: mhonarc - Mail to HTML converter Changes: mhonarc (2.5.2-1.2) stable-security; urgency=high . * Non-maintainer upload by the Security Team * Make sure to htmlize name parameter to avoid any potential XSS. (upstream) * XSS vulnerability with message header fields fixed: Message header field names were not escaped during conversion to HTML. Hence, an attacker could including scripting markup in the message header. (upstream) Files: 8f9fed3cf8291da812c8f286c235aecb 560 mail optional mhonarc_2.5.2-1.2.dsc a2883f16cba2cd5e71bbfc2afa1af67b 4737 mail optional mhonarc_2.5.2-1.2.diff.gz 84fe390991cf60c2ccea131a681a6288 573016 mail optional mhonarc_2.5.2-1.2_all.deb
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQE91A7KW5ql+IAeqTIRAs0XAKCnLIKBs35HTstJIW00vXDtQdNDRQCgqSZP x87wPH70TTkFU9FVbzZQd6c= =h8eS -----END PGP SIGNATURE----- Accepted: mhonarc_2.5.2-1.2.diff.gz to pool/main/m/mhonarc/mhonarc_2.5.2-1.2.diff.gz mhonarc_2.5.2-1.2.dsc to pool/main/m/mhonarc/mhonarc_2.5.2-1.2.dsc mhonarc_2.5.2-1.2_all.deb to pool/main/m/mhonarc/mhonarc_2.5.2-1.2_all.deb