head 1.12; access; symbols RELEASE_5_3_0:1.11 RELEASE_4_10_0:1.8 RELEASE_5_2_1:1.7 RELEASE_5_2_0:1.7 RELEASE_4_9_0:1.7 RELEASE_5_1_0:1.6 RELEASE_4_8_0:1.5 RELEASE_5_0_0:1.5 RELEASE_4_7_0:1.5 RELEASE_4_6_2:1.4 RELEASE_4_6_1:1.4 RELEASE_4_6_0:1.4 old_RELEASE_5_0_DP1:1.2 old_RELEASE_4_5_0:1.2; locks; strict; comment @# @; 1.12 date 2004.12.26.10.33.22; author thierry; state dead; branches; next 1.11; 1.11 date 2004.09.20.21.37.56; author thierry; state Exp; branches; next 1.10; 1.10 date 2004.07.30.17.34.38; author thierry; state Exp; branches; next 1.9; 1.9 date 2004.06.04.20.49.34; author thierry; state Exp; branches; next 1.8; 1.8 date 2004.03.16.22.23.55; author thierry; state Exp; branches; next 1.7; 1.7 date 2003.08.28.23.42.44; author edwin; state Exp; branches; next 1.6; 1.6 date 2003.03.30.00.49.10; author edwin; state Exp; branches; next 1.5; 1.5 date 2002.06.18.07.42.58; author pat; state Exp; branches; next 1.4; 1.4 date 2002.05.23.11.44.31; author sobomax; state Exp; branches; next 1.3; 1.3 date 2002.05.16.08.22.15; author sada; state Exp; branches; next 1.2; 1.2 date 2002.01.19.16.58.08; author ijliao; state Exp; branches; next 1.1; 1.1 date 2001.12.12.20.11.19; author ijliao; state Exp; branches; next ; desc @@ 1.12 log @Remove www/horde2 & mail/imp3 and resurrect www/horde & mail/imp. PR: ports/75434 Submitted by: /me. @ text @MD5 (imp-3.2.6.tar.gz) = 0a12763bef44a1928f59cc72da7d854d SIZE (imp-3.2.6.tar.gz) = 1584426 @ 1.11 log @Upgrade to 3.2.6. Changes in this release: - SECURITY: Removed tags with -moz-binding: styles in the HTML MIME viewer. - SECURITY: Removed scripts from tags in the HTML MIME viewer. - SECURITY: Removed scripts from obfuscated "on..." attributes in the HTML MIME viewer. - Updated translations: Slovak and Slovenian. The script vulnerabilities can only be exposed with certain browsers and allow XSS attacks when viewing HTML messages with the HTML MIME viewer. Approved by: portmgr (marcus) @ text @@ 1.10 log @- SECURITY: Closed an XSS hole in the HTML viewer, a variation to the one reported in http://www.greymagic.com/security/advisories/gm005-mc/. This vulnerability only exists when using the Internet Explorer to access IMP and only when using the inline MIME viewer for HTML messages. - Commented out the complete