Summary
The remote host is missing an update to mhonarc
announced via advisory DSA 199-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20199-1
Insight
Steven Christey discovered a cross site scripting vulnerability in mhonarc, a mail to HTML converter. Carefully crafted message headers can introduce cross site scripting when mhonarc is configured to display all headers lines on the web. However, it is often useful to restrict the displayed header lines to To, From and Subject, in which case the vulnerability cannot be exploited.
This problem has been fixed in version 2.5.2-1.2 for the current stable distribution (woody), in version 2.4.4-1.2 for the old stable distribution (potato) and in version 2.5.13-1 for the unstable distribution (sid).
We recommend that you upgrade your mhonarc package.
Severity
Classification
-
CVE CVE-2002-1307 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities