Gentoo Security Advisory GLSA 200911-01 (horde horde-webmail horde-groupware)

Summary
The remote host is missing updates announced in advisory GLSA 200911-01.
Solution
All Horde users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose =www-apps/horde-3.3.5 All Horde webmail users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose =www-apps/horde-webmail-1.2.4 All Horde groupware users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose =www-apps/horde-groupware-1.2.4 http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200911-01 http://bugs.gentoo.org/show_bug.cgi?id=285052
Insight
Multiple vulnerabilities in the Horde Application Framework can allow for arbitrary files to be overwritten and cross-site scripting attacks.