CVE-2004-0591

Publication date 6 August 2004

Last updated 24 July 2024


Ubuntu priority

Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a “message/delivery-status” MIME Content-Type.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
courier 7.04 feisty
Fixed 0.53.2-3ubuntu1
6.10 edgy
Fixed 0.53.2-3ubuntu1
6.06 LTS dapper
Fixed 0.47-13ubuntu5.1