Updated squirrelmail packages fix security vulnerabilities
Publication date: 08 Jan 2021Modification date: 08 Jan 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-12970
Description
XSS was discovered in SquirrelMail through 1.4.22. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element (). An unsafe use of unserialize() in compose.php has also been fixed.
References
SRPMS
7/core
- squirrelmail-1.4.23-0.svn20201220_0200.1.mga7