Mailing the story:

Debian alert: improper character escaping in fml

  • Mailing list (Posted by on CST)
  • Story Type: Security; Groups: Debian
The fml (a mailing list package) as distributed in Debian GNU/Linux 2.2 suffers from a cross-site scripting problem. When generating index pages for list archives the `<' and `>' characters were not properly escaped for subjects.
What is your name?

What is your E-Mail address?

What is the email address of the recipient?

Add a special note from yourself?