-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Jun 2020 06:47:17 +0200 Source: roundcube Architecture: source Version: 1.4.5+dfsg.1-1~bpo10+1 Distribution: buster-backports Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@alioth-lists.debian.net> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 962123 962124 Changes: roundcube (1.4.5+dfsg.1-1~bpo10+1) buster-backports; urgency=medium . * Rebuild for buster-backports. . roundcube (1.4.5+dfsg.1-1) unstable; urgency=high . * New upstream bugfix release, including security fixes for: - Cross-Site Scripting (XSS) vulnerability via malicious XML messages (closes: #962123) - Cross-Site Scripting (XSS) vulnerability in template object 'username' (closes: #962124) * d/roundcube-core.postinst: Also call ucfr(1) on existing config.inc.php and always pass --debconf-ok to ucf(1). * Bump debhelper compatibility level to 13. * Add upstream meta-information to debian/upstream/metadata. Checksums-Sha1: 88d3f5a167f13280b0aaa7b7cd304c373fdafd48 2498 roundcube_1.4.5+dfsg.1-1~bpo10+1.dsc bbb32519b009fdb7a92c36cfad2309514e458e15 1227964 roundcube_1.4.5+dfsg.1-1~bpo10+1.debian.tar.xz 1614dc64900ee2311ef64a8721d9705530f85f09 9743 roundcube_1.4.5+dfsg.1-1~bpo10+1_amd64.buildinfo Checksums-Sha256: ede623d94ebbc1a74230a11a1cf8e160669033a5b92490d72ce3eb54a0eb17e7 2498 roundcube_1.4.5+dfsg.1-1~bpo10+1.dsc 1110b8497a57b768d7674c7ab3e6848e49bf876f0cdcbc33c1461e76ebfefc2a 1227964 roundcube_1.4.5+dfsg.1-1~bpo10+1.debian.tar.xz 1fc3879cf97d956d3e3a6eec577d11c3aa6e24acec600372f2727bb0bb642929 9743 roundcube_1.4.5+dfsg.1-1~bpo10+1_amd64.buildinfo Files: 2c13573cca5c5c4ee569185d741ac794 2498 web optional roundcube_1.4.5+dfsg.1-1~bpo10+1.dsc 2503544a997e02004f717ce9cc1e38bd 1227964 web optional roundcube_1.4.5+dfsg.1-1~bpo10+1.debian.tar.xz 6254c0ebc73f424a785eaebfc9700178 9743 web optional roundcube_1.4.5+dfsg.1-1~bpo10+1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAl7bIfYACgkQ05pJnDwh pVI4JA//Qq86HCyK+QoCwd3ovgUq4Xhhc7ClLTuLq4QSNbrv0wZplzro0h1DjCAP xVHbtnMC93dpBM6ZCNKnRj1vIC5eCeDMkF0nJAYRFNadV9GDaUFuo+Qpz8JqSKr7 nqLKDkD9ne3mwvdHTPBBNMf45bTm3th/lv16kSd2sq7oADA4PsfHYMDhBSts+J4F k4gqfckScOEnXTaEdL/EEgKDjwkwwbbUQLZMy2VExvN0IFdHv8gevKYY1hH75muA KN54wH+ybRoLXd//Ti9JfB7ih0w8YGAOlJLNV2B/AYxeaWlNvhDYQnP0T9IGtYdL CWhbvpgEoWGXXGP4uO9wP8jIh3oKBksxXoIZhxRKNBvhCm08cJk2+Nyub1BVsSXY bo00lVDgZ6jTyOY6UDzf3KgX6TIkgD+KvAdGmP+ALLHj3iTICPYBGkPnr7YHMGg3 /R9P6jyhaTVMCEcg7dWcbkOD0csj4ucvr7SayFzugoRBf2F8j8GZepHgxFAIFp1g 82v/4G+xLG3Ecdf4u7B7I9UfVVeXGclEJXGGCN34bu+NUGICKfC5P7Thep0FfCvE nvZadGEpbKHpKIYn57EX43wYy+SXiFpqv6a41D81WNb33BGodGbPun4s/3NW473z x9iP2qPRQmLakZcso7SGZlNO/Hd2KGA6N6YEyujFR7ldakQQTsc= =ZPAd -----END PGP SIGNATURE-----