-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 19 May 2024 23:20:59 +0200 Source: roundcube Architecture: source Version: 1.6.7+dfsg-1 Distribution: unstable Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@alioth-lists.debian.net> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 1071474 Changes: roundcube (1.6.7+dfsg-1) unstable; urgency=high . * New upstream bugfix and security release (closes: #1071474): + Fix command injection via crafted im_convert_path/im_identify_path on Windows. + Fix cross-site scripting (XSS) vulnerability in handling list columns from user preferences. + Fix cross-site scripting (XSS) vulnerability in handling SVG animate attributes. + Fix PHP8 warnings. * Update Standards-Version to 4.7.0 (no changes necessary). * Refresh d/patches. Checksums-Sha1: 348b7e0c0dc7cdb4e345ee3a30f89f737531b145 3835 roundcube_1.6.7+dfsg-1.dsc 08be6ab29e5c4a9a75e8aabfa2fcae1a18c6f89e 126884 roundcube_1.6.7+dfsg.orig-tinymce-langs.tar.xz b7bfdde043b8282ca864814db91c8c653403e400 1928628 roundcube_1.6.7+dfsg.orig-tinymce.tar.xz d0af315ebcae325634ac261ec95eefaadf9a50a5 2786052 roundcube_1.6.7+dfsg.orig.tar.xz fa957c14bf3b5d8e33468ec8adf6f5dae06dff91 106492 roundcube_1.6.7+dfsg-1.debian.tar.xz f46b37208e2ff679509ba8bde5a21ae1e51a6d0a 14173 roundcube_1.6.7+dfsg-1_amd64.buildinfo Checksums-Sha256: ea332a1063bbd952f95401a2e8d1222c59765cfc0dd58ab3b8928334a925bf22 3835 roundcube_1.6.7+dfsg-1.dsc d9ad63a033f0324f0b09a8299e9f59bd3c42bdac4d398055971da71ddde4d9fb 126884 roundcube_1.6.7+dfsg.orig-tinymce-langs.tar.xz bcca6ed5234b0c904c12b94e0392c9fb0534dc65c42cb3135aed5050c629df26 1928628 roundcube_1.6.7+dfsg.orig-tinymce.tar.xz fe00780d8a4c73004600574f4cd4392be14190fc610d77dab7a8e88057c620c2 2786052 roundcube_1.6.7+dfsg.orig.tar.xz bb13b1f38471a14d894a5bf9835ccb420a1ef7c78a847d4d68eb95dbb4b2a97b 106492 roundcube_1.6.7+dfsg-1.debian.tar.xz 935fd1c0b6a079bf1bca5315a8a45ae747f1355bb895bb136a1d4446f1a33f23 14173 roundcube_1.6.7+dfsg-1_amd64.buildinfo Files: 17eec622322a69eaeb9e8c191b6855a0 3835 web optional roundcube_1.6.7+dfsg-1.dsc 92efc8a540b02a9771a9d8d61f145594 126884 web optional roundcube_1.6.7+dfsg.orig-tinymce-langs.tar.xz f4f53539e5f76745562cdcdf657a79e3 1928628 web optional roundcube_1.6.7+dfsg.orig-tinymce.tar.xz 4cdb17e640aeda77b719bda7d176245a 2786052 web optional roundcube_1.6.7+dfsg.orig.tar.xz 2c972b619b74643f68a27e7c6266a497 106492 web optional roundcube_1.6.7+dfsg-1.debian.tar.xz 1fb518935d0ce03893a0d279ebc44d39 14173 web optional roundcube_1.6.7+dfsg-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmZKc5kACgkQ05pJnDwh pVLvHg/+MeHNhddm8UT2okKxXv2g6f8SRbssOOKXCUpPjLUkC4KixpcEp8V5qdgW HRTilPHJeKf78J2njEPmelJiabB1E2OIeWpwFHJdJBzsUukoN3TggDoMEfAcnY/1 YLNiTn13QBjFWdDYXjC8p8a3ME+L+BgxYoPiYKNV8J82QJOaOVMJypgR0sS2Y81/ XcVKPiGJEja0ytDDjAbYU4B0G56go+85EUok4ykRQP2Jz6/8QYHYUGjW0VRyR1jF rl7/zCwZjcGolnOc5uDyf0+f7s48zfLclvfk7opmaL1wkjIDB+T6+H/xfRuufKmX kYZRmQedQDijZcePhWGUslQlgYKACQQxiwq6ozEcv1ph7cB5lZrn3+7/On6d0YVh oRw0Kk8Ol/DIGzZMEOdHM7CyELlqfBik0CXNGv4yah2j1/BxQC8uD5nTFnsV2dik q0n1xArdfxFvvFEC1LxsHCsHg8xw9Q56nh2uJGjjEpIrtxRBY8ep6O5/G5Hkh72h L3ndnmt8HWNzTGL3nj3upi57mhzUrIhy+3GCJNDRj3z83/1Vwcsfjs7dgV2I2P4f EYAQCmWwPcteEVZHiwhPMZIkWtYW+3BvE6Ex7CZA+FKvHtD2CNrQjzzdorweQHmD XPUrmiHbzA9M1FDz68ciXn3UQb9iTqN4FahVezHz5O+aK5F9ejI= =lXZ9 -----END PGP SIGNATURE-----
Attachment:
pgp4gLBXorEx6.pgp
Description: PGP signature