• Roundcube Webmail 1.4.5

    From Dominic Hargreaves@21:1/5 to Guilhem Moulin on Wed Jun 3 21:00:02 2020
    On Wed, Jun 03, 2020 at 01:51:40PM +0200, Guilhem Moulin wrote:
    Hi,

    On Wed, 03 Jun 2020 at 12:34:09 +0100, David Pottage wrote:
    Roundcube have just announced a new release which includes security
    fixes.

    What is the timeline to updated the Debian package in backports?

    I'm preparing an upload to unstable, from there it should take 2 more
    days (like for 1.4.4).

    Thanks for working on roundcube in Debian! Do you know what the
    story is with these vulnerabilities and stable/oldstable? I note that
    there is no 1.2.x release in this advisory even though there was
    just over a month ago (and there it was described as being LTS).
    I couldn't find anything about whether the vulnerabilities apply
    to 1.2 or any change to the 1.2.x support status.

    Cheers
    Dominic

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Guilhem Moulin@21:1/5 to Dominic Hargreaves on Wed Jun 3 21:20:02 2020
    Hi Dominic,

    On Wed, 03 Jun 2020 at 19:53:48 +0100, Dominic Hargreaves wrote:
    Do you know what the story is with these vulnerabilities and stable/oldstable?

    Roundcube from Buster and Stretch are both affected, see #962123 and
    #962124. Will prepare debdiffs tonight.

    Cheers,
    --
    Guilhem.

    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAl7X8/8ACgkQ05pJnDwh pVLRLQ//XEPA/IFerxV1jN7LxuiIBPD2PJJrFkRd0DblIug4dDtqEAeQaRVgdQSf xUyutlEXBOPxet7jgGuGMfGkBvvXHWGSJRFRxryRVnPWElOv46cRdTul5QdFbRZQ Y/LySXlymF5oDqfPDVnaMEBuP7DTvXzZLB1i3J1uaC3xZecibkZzQ4VPNtJJyQOD ujFH6eFYDbLGt4pZr5wSFXMVx1rKRsc3fqrlfIzuxVOhbKOMHT4YH5c89mkkpO9J VC75Zxd6HpF2mvd8qXY7RLiDZYarIcO4K4QXsRg8p3nKT0XBv8zmVxbC3NjqHu6K fNId0b7TaOpATp/pRic/md1Cq8WdWPDI+X3tIxfk5/TVHeUbYqZE32Rs+DD1MGd/ Y3JYE2ERPuJzU1j4f1nw2fV5bteyDAjmpNbwICtvBBjAMo5IDYo3OnHqZ0NQx2cr VC5Y/PYlI3Tov2mNuyeavEpqUwltuDXlihUhTMiGIg7lEE3q+aOgbjXGoTL6DRUt 85QC5Ug0SCWGUMlUqqd7t6/sBdVuZbnx9mNdDHfAkdZ10tdEG68p/JNYiSBONeFn vMiOUlmSvqvBPDMeewXg9jH2rbH48vM1UT/qfBK9HgZDIR3gkgO+Y6/v3PPAv727 jmUYRp6Eh1bB0VBg+V3v21t3fYTgj95lZk77sfthIcFDboc40DI=
    =w3mB
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)