Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 30 Jul 2004 17:34:38 +0000 (UTC)
From:      Thierry Thomas <thierry@FreeBSD.org>
To:        ports-committers@FreeBSD.org, cvs-ports@FreeBSD.org, cvs-all@FreeBSD.org
Subject:   cvs commit: ports/mail/imp3 Makefile distinfo
Message-ID:  <200407301734.i6UHYcwh093460@repoman.freebsd.org>

next in thread | raw e-mail | index | archive | help
thierry     2004-07-30 17:34:38 UTC

  FreeBSD ports repository

  Modified files:
    mail/imp3            Makefile distinfo 
  Log:
  - SECURITY: Closed an XSS hole in the HTML viewer, a variation to the one
    reported in http://www.greymagic.com/security/advisories/gm005-mc/.
    This vulnerability only exists when using the Internet Explorer to
    access IMP and only when using the inline MIME viewer for HTML messages.
  
  - Commented out the complete <style> tags in the HTML viewer to avoid CSS
    code appearing in the message.
  
  - Fixed a cosmetic issue with broken mail servers that return quotes where
    they should not (Bug #292).  <- edwin ;-)
  
  - Updated translations: Estonian, German.
  
  Revision  Changes    Path
  1.34      +1 -1      ports/mail/imp3/Makefile
  1.10      +2 -2      ports/mail/imp3/distinfo



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200407301734.i6UHYcwh093460>