SquirrelMail is een in PHP geschreven programma om webbased e-mail mogelijk te maken. Het wordt door verschillende internet providers gebruikt om webmail functionaliteiten aan te bieden. Het programma heeft ondersteuning voor de IMAP- en SMTP-protocollen en alle schermen worden in HTML 4.0 opgebouwd, zonder dat hiervoor JavaScript nodig is. De ontwikkelaars hebben versie 1.4.9a de deur uit gedaan met de volgende aankondigingen sinds de vorige vermelding in de meuktracker:
Version 1.4.9aThe SquirrelMail Project Team is proud to announce the release of SquirrelMail 1.4.9a. The day after we released SquirrelMail 1.4.9 new cross site scripting issues were reported and immediately fixed. Therefor the decision to release 1.4.9a so short after the 1.4.9 release. The 1.4.9a release contains multiple fixes for cross site scripting issues triggered by viewing html mail with Internet Explorer upto version 5. The 1.4.9 release contains a fix for cross site scripting issues, a workaround for an issue in Internet Explorer and a collection of regular bugfixes. Details on all the changes in this release can be found in the ChangeLog and under the security section of our website.
Version 1.4.9
Happy SquirrelMailing!The SquirrelMail Project Team is proud to announce the release of SquirrelMail 1.4.9. This release contains a fix for cross site scripting issues, a workaround for an issue in Internet Explorer and a collection of regular bugfixes. Details on all the changes in this release can be found in the ChangeLog and under the security section of our website.
Version 1.4.8
Happy SquirrelMailing!The SquirrelMail Project Team is proud to announce the release of SquirrelMail 1.4.8. This release contains an important security fix where a logged-in user could overwrite variables, and a collection of regular bugfixes. Details on all the changes in this release can be found in the ChangeLog. There's also two patches available against the 1.4.7 release for just the security issue: a minimal one that removes the function, because it was broken anyway, or more extended one which fixes the functionality and closes the hole.
Happy SquirrelMailing!