-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 29 Jan 2009 03:17:37 +0100 Source: horde3 Binary: horde3 Architecture: source all Version: 3.1.3-4etch5 Distribution: oldstable-security Urgency: high Maintainer: Horde Maintainers <pkg-horde-hackers@lists.alioth.debian.org> Changed-By: Gregory Colpart <reg@debian.org> Description: horde3 - horde web application framework Closes: 492578 512592 513265 Changes: horde3 (3.1.3-4etch5) oldstable-security; urgency=high . * Backport a patch from Horde upstream to fix an IE-only hole in XSS filter (See CVE-2008-5917 for more information). (Closes: #512592) * Backport a patch from Horde upstream to fix a file inclusion issue in Horde_Image driver name (Image/Image.php). (Closes: #513265) * Fix small XSS/unescaped output vulnerability in services/obrowser/index.php (see CVE-2008-3330 for more informations). (Closes: #492578) Checksums-Sha1: 4737899db54692f66244a11d869172126b4fb998 1076 horde3_3.1.3-4etch5.dsc 43dda35c02ec503fcbff42ee1f07187edb2bde24 13749 horde3_3.1.3-4etch5.diff.gz 0be19171ea216a60ebd21c5bda24a6c25d363e03 5274074 horde3_3.1.3-4etch5_all.deb Checksums-Sha256: a245387839313fb208accc2bd018e19bc5be464cad1a6a269f43a0a866f493e2 1076 horde3_3.1.3-4etch5.dsc 0b4f4fb788e890c4cb66bcb89a3ba6257ed397f98c230ecd2136a95057e7aab1 13749 horde3_3.1.3-4etch5.diff.gz 6533c12f50134550558b54894536f32f66c455288ded8c730673bee1045ca0f6 5274074 horde3_3.1.3-4etch5_all.deb Files: c6082f3a21860b6b65b7edc4c58b0c07 1076 web optional horde3_3.1.3-4etch5.dsc d7ad332e2f535b9df1ab49bd9c7233fa 13749 web optional horde3_3.1.3-4etch5.diff.gz e4cfd0484345a153c33481101472a1fe 5274074 web optional horde3_3.1.3-4etch5_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAknY8iUACgkQMhdcDcECeg5ZGQCfSpIZtGiyXj+E1a22wtZIS7kE +PgAn1BAMoGxJ0iJjLc/fWJqovUXY1Qv =y3R8 -----END PGP SIGNATURE----- Accepted: horde3_3.1.3-4etch5.diff.gz to pool/main/h/horde3/horde3_3.1.3-4etch5.diff.gz horde3_3.1.3-4etch5.dsc to pool/main/h/horde3/horde3_3.1.3-4etch5.dsc horde3_3.1.3-4etch5_all.deb to pool/main/h/horde3/horde3_3.1.3-4etch5_all.deb