-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 04 May 2020 14:50:42 +0200 Source: roundcube Binary: roundcube-core roundcube roundcube-mysql roundcube-pgsql roundcube-sqlite3 roundcube-plugins Architecture: source Version: 1.2.3+dfsg.1-4+deb9u4 Distribution: stretch-security Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@lists.alioth.debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Description: roundcube - skinnable AJAX based webmail solution for IMAP servers - metapack roundcube-core - skinnable AJAX based webmail solution for IMAP servers roundcube-mysql - metapackage providing MySQL dependencies for RoundCube roundcube-pgsql - metapackage providing PostgreSQL dependencies for RoundCube roundcube-plugins - skinnable AJAX based webmail solution for IMAP servers - plugins roundcube-sqlite3 - metapackage providing SQLite dependencies for RoundCube Closes: 959140 959142 Changes: roundcube (1.2.3+dfsg.1-4+deb9u4) stretch-security; urgency=high . * Backport security fixes from 1.2.10: - CVE-2020-12625: Cross-Site Scripting (XSS) vulnerability via malicious HTML messages (closes: #959140) - CVE-2020-12626: CSRF attack can cause an authenticated user to be logged out (closes: #959142) Checksums-Sha1: cea61cb05007bd024d3647094dcae5a28187f969 2472 roundcube_1.2.3+dfsg.1-4+deb9u4.dsc c0d5e9e973e2eed24a61e9aba61339ca4bf59d5b 4446576 roundcube_1.2.3+dfsg.1-4+deb9u4.debian.tar.xz 44f8b5be0ada1cc6d7bfe3d042a26964b316da27 9679 roundcube_1.2.3+dfsg.1-4+deb9u4_amd64.buildinfo Checksums-Sha256: c373e99d8dba03f43f6a3bf5bd79a0ee2f5549e85f24e0ec99f588d37fdf01ca 2472 roundcube_1.2.3+dfsg.1-4+deb9u4.dsc a473a75a851f875e7c060abde8eff0c1d1f8c320c8602e92c6e9541816422556 4446576 roundcube_1.2.3+dfsg.1-4+deb9u4.debian.tar.xz 9391342a66d27937da8f4a5b41ce18ac51459974c9a2dc07f931030c66e20823 9679 roundcube_1.2.3+dfsg.1-4+deb9u4_amd64.buildinfo Files: 9fa83fa2f3bd52f6d65cc55e73c3f009 2472 web extra roundcube_1.2.3+dfsg.1-4+deb9u4.dsc aebf0aa3aec8722febd7a75655f0f32b 4446576 web extra roundcube_1.2.3+dfsg.1-4+deb9u4.debian.tar.xz bd8a1706a17bedcf3f44b416971bb155 9679 web extra roundcube_1.2.3+dfsg.1-4+deb9u4_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAl6wFi4ACgkQ05pJnDwh pVKGRQ//TlO841DOdjzwJE7v6fv6S1fvDy374mekWKiZCXh8jeLmkE3VFsOTW3AV iJD1v8fsUzGUYDgDelU/iq/2U9w2DH9j1BwlMQy7hqPZCH3YXsF+fdZNAIBdpo3n gSLjatjIxBo7RwV31Bd7ytj15xUJi1OYV2nfHLd6+2ZwTA5oMt4OnY3emCHM7Ewc aSo2CM5WAlUwQZGhIk138l684uy2ctpfrwWEqmOC2K/qI75nYjPuUhhpTnLegTWA fofEOHxYoY40M7jXFxGn7ZeI1K+JBRCuSCxcdcDJ2b3mw5f6jRlHeuFrJQch2n91 G2lHdABOgfcT7wpEaAuXuA8DB5L7CbMGz9nzk3Yx/z+vg4qLg0cZL+P9YKlHuDd5 amU/jgB6K9TAlvzBs0yrWcQguSn0A8MuBzYus4KAaSbOCB7guf4tDiDvzNQ0xxAQ qQXhgActUMs8iDxnv7uY0SHVXpC5q3ZmFwF0ox33XyR3bb8IoMyBsHx+hrKTASwo ub1Ge6MJpjHHZ1hiFxjJ0MzLacc4m2UnGNfOFXqWlO838lI9ZgilDjMDdYekaGV6 fLb1IpOTl5QaXXq/PiLLJLoNBrO9+UY0KQYUUSPwuEyBj26rCv5f+LKoS2/PpT3V KljkZGtH5xdpjrvVEa3h+VF2MdrloeBsOoW7PqST29QdHvY4Kbw= =E+Dx -----END PGP SIGNATURE-----