-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.6 Date: Thu, 14 Nov 2002 21:47:45 +0100 Source: mhonarc Binary: mhonarc Architecture: source all Version: 2.4.4-1.2 Distribution: oldstable-security Urgency: high Maintainer: Martin Schulze Description: mhonarc - Mail to HTML converter Changes: mhonarc (2.4.4-1.2) oldstable-security; urgency=high . * Non-maintainer upload by the Security Team * XSS vulnerability with message header fields fixed: Message header field names were not escaped during conversion to HTML. Hence, an attacker could including scripting markup in the message header. (upstream) Files: 437de7328103a84b6916a1baaa61f477 538 - - mhonarc_2.4.4-1.2.dsc 90646c64bc07c9c6c5264e2a87fb16f3 6272 - - mhonarc_2.4.4-1.2.diff.gz 8e7f1a40ff78e0bef2d1c9593545baee 453352 - - mhonarc_2.4.4-1.2_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQE91A4hW5ql+IAeqTIRAlqyAJ427OFWDocG2SxfUo4fpAQk770vlQCgoxr5 E34Kpjbp19pCiINsiCeiGaI= =Kv1h -----END PGP SIGNATURE-----