From b14d49a80cbd221b168fcdb8d53e012502d00a31 Mon Sep 17 00:00:00 2001 From: Thierry Thomas Date: Tue, 23 Nov 2010 19:02:12 +0000 Subject: [PATCH] Add an entry for www/horde-base VCARD attachments XSS vulnerability. Security: VuXML: a3314314-f731-11df-a757-0011098ad87f --- security/vuxml/vuln.xml | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 775886d407d0..cbad24e49a33 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,33 @@ Note: Please add new entries to the beginning of this file. --> + + horde-base -- XSS: VCARD attachments vulnerability + + + horde-base + 3.3.11 + + + + +

The Horde team reports:

+
+

The major changes compared to Horde version 3.3.10 are:

+

* Fixed XSS vulnerability when viewing details of a vCard.

+
+ +
+ + http://article.gmane.org/gmane.comp.horde.announce/532 + http://bugs.horde.org/ticket/9357 + + + 2010-11-02 + 2010-11-23 + +
+ proftpd -- remote code execution vulnerability