IMP_MIME_Viewer_html class XSS vulnerabilities

Summary
The remote server is running at least one instance of IMP whose version number is between 3.0 and 3.2.1 inclusive. Such versions are vulnerable to several cross-scripting attacks whereby an attacker can cause a victim to unknowingly run arbitrary Javascript code simply by reading an HTML message from the attacker. Announcements of the vulnerabilities can be found at : - http://marc.theaimsgroup.com/?l=imp&m=105940167329471&w=2 - http://marc.theaimsgroup.com/?l=imp&m=105981180431599&w=2 - http://marc.theaimsgroup.com/?l=imp&m=105990362513789&w=2 Note : OVS has determined the vulnerability exists on the target simply by looking at the version number of IMP installed there. If the installation has already been patched, consider this a false positive.
Solution
Upgrade to IMP version 3.2.2 or later or apply patches found in the announcements to imp/lib/MIME/Viewer/html.php.