Jan Schneider | 13 Nov 2005 12:47
Favicon
Gravatar

Kronolith H3 (2.0.5) (final)

The Horde Team is pleased to announce the final release of the Kronolith
Calendar Application version H3 (2.0.5).

Kronolith is the Horde calendar application.  It provides web-based calendars
backed by a SQL database, the MCAL library, or a Kolab server.  Supported
features include shared calendars, remote calendars, meeting management,
alarms, recurring events, and a sophisticated day/week view which handles
arbitrary numbers of overlapping events.

Major changes compared to the Kronolith version H3 (2.0.4) are:
    * Fix reminder emails.
    * Fix warnings with Internet Explorer on HTTPS connections.

The full list of changes (from version H3 (2.0.4)) can be viewed here:

http://cvs.horde.org/diff.php/kronolith/docs/CHANGES?r1=1.165.2.68&r2=1.165.2.69.2.1&ty=h

The Kronolith H3 (2.0.5) distribution is available from the following locations:

    ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.0.5.tar.gz
    http://ftp.horde.org/pub/kronolith/kronolith-h3-2.0.5.tar.gz

Patches against version H3 (2.0.4) are available at:

    ftp://ftp.horde.org/pub/kronolith/patches/patch-kronolith-h3-2.0.4-h3-2.0.5.gz
    http://ftp.horde.org/pub/kronolith/patches/patch-kronolith-h3-2.0.4-h3-2.0.5.gz

Or, for quicker access, download from your nearest mirror:

    http://www.horde.org/mirrors.php
(Continue reading)

Jan Schneider | 13 Nov 2005 13:12
Favicon
Gravatar

Horde 2.2.9 (final)

The Horde Team is pleased to announce the final release of the Horde
Application Framework version 2.2.9. Note that this is not the current stable
version of the framework, but the old deprecated version, which will soon be
discontinued.

The Horde Application Framework is a general-purpose web application
framework in PHP, providing classes for dealing with preferences,
compression, browser detection, connection tracking, MIME handling and
more.

Changes in this release:
    * Fixed a potential XSS vulnerability.

The full list of changes (from version 2.2.8) can be viewed here:

http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.207.2.109&r2=1.207.2.111&ty=h

The Horde 2.2.9 distribution is available from the following locations:

    ftp://ftp.horde.org/pub/horde/horde-2.2.9.tar.gz
    http://ftp.horde.org/pub/horde/horde-2.2.9.tar.gz

Patches against version 2.2.8 are available at:

    ftp://ftp.horde.org/pub/horde/patches/patch-horde-2.2.8-2.2.9.gz
    http://ftp.horde.org/pub/horde/patches/patch-horde-2.2.8-2.2.9.gz

Or, for quicker access, download from your nearest mirror:

    http://www.horde.org/mirrors.php
(Continue reading)

Jan Schneider | 22 Nov 2005 18:09
Favicon
Gravatar

Horde 3.0.7 (final)

The Horde Team is pleased to announce the final release of the Horde
Application Framework version 3.0.7.

This is a security release that fixes cross site scripting vulnerabilities in
two of Horde's MIME viewers. These holes could for example be exploited by an
attacker sending specially crafted emails to Horde's webmail client IMP. The
attack could be used to steal users' identity information, taking over users'
sessions, or changing users' settings.

As a hotfix the css and tgz MIME drivers can be disabled by removing their
entries from the $mime_drivers_map['horde']['registered'] list in
horde/config/mime_drivers.php. Alternatively these two patches could be
applied to lib/Horde/MIME/Viewer/tgz.php and lib/Horde/MIME/Viewer/css.php:
http://cvs.horde.org/diff.php/framework/MIME/MIME/Viewer/tgz.php?r1=1.37.10.9&r2=1.37.10.9.2.1&ty=u
http://cvs.horde.org/diff.php/framework/MIME/MIME/Viewer/css.php?r1=1.1.10.3&r2=1.1.10.3.2.1&ty=u

Many thanks to Daniel Schreckling who discovered this vulnerability.

The Horde Application Framework is a modular, general-purpose web application
framework written in PHP.  It provides an extensive array of classes that are
targeted at the common problems and tasks involved in developing modern web
applications.

Major changes compared to the Horde version 3.0.6 are:
    * Fixed cross site scripting vulnerabilities in the gzip/tar and css MIME
      viewers.
    * Fixed MySQL session handler.

The full list of changes (from version 3.0.6) can be viewed here:

(Continue reading)


Gmane