REDHAT-BUG-641069: XSS
Upstream has released a new version of IMP (4.3.8) [1] that corrects the following flaw [2],[3]:
Fixed an XSS vulnerability in the Fetchmail configuration.
This has been assigned the name CVE-2010-3695. The current version of IMP in Fedora is 4.3.7 and is vulnerable to this flaw.
[1] http://lists.horde.org/archives/announce/2010/000557.html [2] http://git.horde.org/diff.php/imp/fetchmailprefs.php?rt=horde&r1=1.39.4.10&r2=1.39.4.11 [3] http://archives.neohapsis.com/archives/fulldisclosure/2010-09/0379.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-641069?
The severity of REDHAT-BUG-641069 is related to an XSS vulnerability which can lead to security risks if not addressed.
How do I fix REDHAT-BUG-641069?
To fix REDHAT-BUG-641069, upgrade your Horde IMP installation to version 4.3.8 or later.
What vulnerabilities are addressed in REDHAT-BUG-641069?
REDHAT-BUG-641069 addresses an XSS vulnerability found in the Fetchmail configuration.
Which software is affected by REDHAT-BUG-641069?
The affected software for REDHAT-BUG-641069 is the Horde IMP framework.
Is there a patch available for REDHAT-BUG-641069?
Yes, the patch is included in the release of Horde IMP version 4.3.8.