Bugzilla – Bug 872334
VUL-0: CVE-2012-6640: horde5-imp: XSS vulnerabilities triggered by opening malicious SVG attachments
Last modified: 2016-04-13 11:20:49 UTC
CVE-2012-6640 Malicious SVG attachments can be used to trigger a XSS. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-6640 http://www.cvedetails.com/cve/CVE-2012-6640/ http://lists.horde.org/archives/announce/2012/000775.html https://github.com/horde/horde/commit/08c699f744b6d2be1a5f3a2ba7203f4631b4c5dc
bugbot adjusting priority
a statement or fix of this would be nice, Ralf?
ping
Sorry, this got lost. - An updated version which is not affected exists in both server:php:applications and isv:b1-systems:Horde5:rolling - These have also upgraded dependencies Shall I do one "maint. request" against 13.1 with all packages which would need to be changed/added or shall I submit multiple maint. requests each for one package?
(In reply to Ralf Lang from comment #4) How much would you have to include in one request (which I would prefer)?
ping. What packages would you need to include?
fixed in all maintained versions