-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Mon, 11 Dec 2006 14:53:09 +0100 Source: squirrelmail Binary: squirrelmail Architecture: source all Version: 2:1.4.4-10 Distribution: stable-security Urgency: high Maintainer: Jeroen van Wolffelaar <jeroen@wolffelaar.nl> Changed-By: Thijs Kinkhorst <thijs@debian.org> Description: squirrelmail - Webmail for nuts Changes: squirrelmail (2:1.4.4-10) stable-security; urgency=high . * Fix cross site scripting in malicious input the mailto parameter of webmail.php, the session and delete_draft parameters of compose.php, and via a shortcoming in the magicHTML filter. [CVE-2006-6142] * Work around dangerous Internet Explorer MIME type guessing. http://www.squirrelmail.org/security/issue/2006-12-03 * Patches from upstream. Files: cc443dbfaaf32fc0f157bc9dee46c937 680 web optional squirrelmail_1.4.4-10.dsc 5a19e089f41344b4a8a556ced2da3917 28247 web optional squirrelmail_1.4.4-10.diff.gz f5f9f495411c7bdc3455a1e3b0598352 571102 web optional squirrelmail_1.4.4-10_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFFfWnVJdKMxZV9WM8RAk2xAJ0deTH0/oUr4a8NoNrxl/UaOucWgACgrelo 2fObAVv7oduxydTdThQB7bo= =Rxq+ -----END PGP SIGNATURE----- Accepted: squirrelmail_1.4.4-10.diff.gz to pool/main/s/squirrelmail/squirrelmail_1.4.4-10.diff.gz squirrelmail_1.4.4-10.dsc to pool/main/s/squirrelmail/squirrelmail_1.4.4-10.dsc squirrelmail_1.4.4-10_all.deb to pool/main/s/squirrelmail/squirrelmail_1.4.4-10_all.deb