<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Giuseppe, il suo blog &#187; atmailopen</title>
	<atom:link href="http://www.iuculano.it/en/tag/atmailopen/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.iuculano.it</link>
	<description></description>
	<lastBuildDate>Wed, 08 Sep 2010 10:53:24 +0000</lastBuildDate>
	<language>it-it</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>I’m thinking to ask for removal of atmailopen in Debian</title>
		<link>http://www.iuculano.it/en/linux/im-thinking-to-ask-for-removal-of-atmailopen-in-debian/</link>
		<comments>http://www.iuculano.it/en/linux/im-thinking-to-ask-for-removal-of-atmailopen-in-debian/#comments</comments>
		<pubDate>Fri, 22 May 2009 12:59:30 +0000</pubDate>
		<dc:creator>Giuseppe</dc:creator>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[atmailopen]]></category>

		<guid isPermaLink="false">http://www.iuculano.it/?p=67</guid>
		<description><![CDATA[From December 2008, I maintain the atmailopen Debian pa [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>From December 2008, I maintain the <a title="Atmailopen Debian package" href="http://packages.qa.debian.org/a/atmailopen.html" target="_blank">atmailopen Debian package</a>. This is a nice webmail in PHP and Ajax , it aim to provide an elegant Ajax webmail client for existing IMAP mailservers, with less bloat and a focus on an intuitive, simple user interface.</p>
<p>I was very happy when it was accepted in Debian, but I was wrong:</p>
<p>On 19/04/2009 I noticed a Secunia advisory about @Mail (<a href="http://secunia.com/advisories/34704/" target="_blank">SA34704</a>) ,and the same day I mailed upstream and asked if atmailopen is affected by the same security vulnerability.  No answer as of today, 2009-05-22 &#8230;</p>
<p>While checking about SA34704, I discovered that atmailopen is using the vulnerable version of html2text, which could lead to code execution attacks, the same of <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5619" target="_self">CVE-2008-5619</a> in roundcube.</p>
<p>On 26/04/2009 I mailed upstream to inform about this issue, but as usual, nothing&#8230; no answer as of today, 2009-05-22 &#8230;</p>
<p>Is clearly evident, upstream doesn&#8217;t take care about security in his atmail open source version, and doesn&#8217;t provide security support.</p>
<p>This is not acceptable for a software in Debian, I will request a removal.</p>
<p>P.S. If you aren&#8217;t using the debian package, I really suggest you to <a href="http://patch-tracking.debian.net/patch/series/view/atmailopen/1.03+dfsg+svn93-5/02_fix_html2text_code_injection.patch">patch</a> your atmailopen version, or better, switch to another webmail.</p>
<p>UPDATE:  atmailopen was <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=531075" target="_blank">removed</a> from Debian
<ul class="lang_switch">
<li class="lang_switch"><a href="http://www.iuculano.it/it/linux/im-thinking-to-ask-for-removal-of-atmailopen-in-debian/"><img src="http://www.iuculano.it/wp-content/plugins/zdmultilang/flags/it_IT.png" alt="Italian" title="Italian" border="0">Italian</a></li>
</ul>
<img src="http://www.iuculano.it/?ak_action=api_record_view&id=67&type=feed" alt="" />

<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.iuculano.it/en/linux/im-thinking-to-ask-for-removal-of-atmailopen-in-debian/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
