Bug#355424: squirrelmail: Security Bugs in 1.4.4

2006-03-06 Thread Thijs Kinkhorst
On Mon, 2006-03-06 at 18:40 +0100, Jochen Topf wrote: > On Mon, Mar 06, 2006 at 06:10:19PM +0100, Thijs Kinkhorst wrote: > > > But the stable version 1.4.4 hasn't changed since > > > August of last year. > > > > There has been an update of the stable version in Sarge 3.1r1 in > > December. If you

Bug#355424: squirrelmail: Security Bugs in 1.4.4

2006-03-06 Thread Jochen Topf
On Mon, Mar 06, 2006 at 06:10:19PM +0100, Thijs Kinkhorst wrote: > > But the stable version 1.4.4 hasn't changed since > > August of last year. > > There has been an update of the stable version in Sarge 3.1r1 in > December. If you've not received that update, something's probably > broken on you

Bug#355424: squirrelmail: Security Bugs in 1.4.4

2006-03-06 Thread Thijs Kinkhorst
Hello, Thanks for your report. On Sun, 2006-03-05 at 16:34 +0100, Jochen Topf wrote: > There are several security fixes in squirrel mail 1.4.6 which came out > 23 February 2006. Yes, indeed. There are bugs filed about that. I'm already working on packages that fix those issues, it's taken a litt

Bug#355424: squirrelmail: Security Bugs in 1.4.4

2006-03-05 Thread Jochen Topf
Package: squirrelmail Version: 2:1.4.4-7 Severity: grave Tags: security Justification: user security hole There are several security fixes in squirrel mail 1.4.6 which came out 23 February 2006. But the stable version 1.4.4 hasn't changed since August of last year. See http://www.squirrelmail.or