Summary
The remote host is missing an update to imp
announced via advisory DSA 126-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20126-1
Insight
A cross-site scripting (CSS) problem was discovered in Horde and IMP (a web based IMAP mail package). This was fixed upstream in Horde version 1.2.8 and IMP version 2.2.8. The relevant patches have been back-ported to version 1.2.6-0.potato.5 of the horde package and version 2.2.6-0.potato.5 of the imp package.
This release also fixes a bug introduced by the php security fix from DSA-115-1: the php postgres support changed subtle which broke the postgres support from imp.
Severity
Classification
-
CVE CVE-2002-0181 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities