CVE-2008-2379

Publication date 5 December 2008

Last updated 24 July 2024


Ubuntu priority

Description

Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.

Status

Package Ubuntu Release Status
squirrelmail 8.10 intrepid
Fixed 2:1.4.15-3ubuntu0.1
8.04 LTS hardy
Fixed 2:1.4.13-2ubuntu1.1
7.10 gutsy
Fixed 2:1.4.10a-2ubuntu0.1
6.06 LTS dapper
Fixed 2:1.4.6-1ubuntu0.2