FreeBSD : horde-base -- XSS: VCARD attachments vulnerability (a3314314-f731-11df-a757-0011098ad87f)

high Nessus Plugin ID 50701

Language:

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

The Horde team reports :

The major changes compared to Horde version 3.3.10 are :

* Fixed XSS vulnerability when viewing details of a vCard.

Solution

Update the affected package.

See Also

http://article.gmane.org/gmane.comp.horde.announce/532

https://bugs.horde.org/ticket/9357

http://www.nessus.org/u?6774570d

Plugin Details

Severity: High

ID: 50701

File Name: freebsd_pkg_a3314314f73111dfa7570011098ad87f.nasl

Version: 1.9

Type: local

Published: 11/24/2010

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:horde-base, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 11/23/2010

Vulnerability Publication Date: 11/2/2010