Candidate: CVE-2008-2379 PublicDate: 2008-12-05 00:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2379 Description: Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_squirrelmail: upstream_squirrelmail: released (1.4.17) dapper_squirrelmail: released (2:1.4.6-1ubuntu0.2) gutsy_squirrelmail: released (2:1.4.10a-2ubuntu0.1) hardy_squirrelmail: released (2:1.4.13-2ubuntu1.1) intrepid_squirrelmail: released (2:1.4.15-3ubuntu0.1) devel_squirrelmail: not-affected