Family: Debian Local Security Checks --> Category: infos
[DSA126] DSA-126-1 imp Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
A cross-site scripting (CSS) problem was discovered in Horde and IMP (a web
based IMAP mail package). This was fixed upstream in Horde version 1.2.8
and IMP version 2.2.8. The relevant patches have been back-ported to
version 1.2.6-0.potato.5 of the horde package and version 2.2.6-0.potato.5
of the imp package.
This release also fixes a bug introduced by the PHP security fix from
DSA-115-1: Postgres support for PHP was changed
in a subtle way which broke the Postgres support from IMP.
Solution : http://www.debian.org/security/2002/dsa-126
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.