-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 09 Jun 2020 13:46:01 +0200 Source: roundcube Binary: roundcube-core roundcube roundcube-mysql roundcube-pgsql roundcube-sqlite3 roundcube-plugins Architecture: source Version: 1.2.3+dfsg.1-4+deb9u5 Distribution: stretch-security Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@lists.alioth.debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Description: roundcube - skinnable AJAX based webmail solution for IMAP servers - metapack roundcube-core - skinnable AJAX based webmail solution for IMAP servers roundcube-mysql - metapackage providing MySQL dependencies for RoundCube roundcube-pgsql - metapackage providing PostgreSQL dependencies for RoundCube roundcube-plugins - skinnable AJAX based webmail solution for IMAP servers - plugins roundcube-sqlite3 - metapackage providing SQLite dependencies for RoundCube Closes: 962123 962124 Changes: roundcube (1.2.3+dfsg.1-4+deb9u5) stretch-security; urgency=high . * Backport security fixes from 1.3.12: - CVE-2020-13964: Cross-Site Scripting (XSS) vulnerability in template object 'username' (closes: #962124) - CVE-2020-13965: Cross-Site Scripting (XSS) vulnerability via malicious XML messages (closes: #962123) Checksums-Sha1: 29ac1a9ae5d033183b6b30c204a0fe4e70f12b7e 2472 roundcube_1.2.3+dfsg.1-4+deb9u5.dsc 76c516e3139be3f54088b0c16e6292ceb865d880 4447448 roundcube_1.2.3+dfsg.1-4+deb9u5.debian.tar.xz c3044eca4065ee3ad830dc20fa037361e02f81b2 9679 roundcube_1.2.3+dfsg.1-4+deb9u5_amd64.buildinfo Checksums-Sha256: 93091be8beb4a47d8c2fed7aca7830efbe6b7367d82abc96e18dacd0c1d1df8a 2472 roundcube_1.2.3+dfsg.1-4+deb9u5.dsc 089b48e7f3653a3cd51a1447a06d998554997fff5e4ced3e0da0045533d5d9f2 4447448 roundcube_1.2.3+dfsg.1-4+deb9u5.debian.tar.xz 79f258ca32f18de94b81423670380e7639246ce8e938ad5fc3fcb97da4793660 9679 roundcube_1.2.3+dfsg.1-4+deb9u5_amd64.buildinfo Files: 07c026dfb98ab33f204e4b5cef93cd00 2472 web extra roundcube_1.2.3+dfsg.1-4+deb9u5.dsc 02634b03c91e91eeb41d2f9c6d229c28 4447448 web extra roundcube_1.2.3+dfsg.1-4+deb9u5.debian.tar.xz 242d16758e93eb14b6b37e4c1fc203aa 9679 web extra roundcube_1.2.3+dfsg.1-4+deb9u5_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAl7fd1YACgkQ05pJnDwh pVL4zg//f+rH0/HxlAxSsYKGzEeBSqkC43l0s0RQKDRKKPM8AjztKjNqwD3joxau aIEldD8WlNpIoPq7Pp+iSZ38WZ665ZBvt3nujNAvfqE6PCcvF0k30rw3pPHWI0gg RKkZebb/1Pm3jyD1WlXnJzEdpl+fxFWpMIwk+U0yqvichJLUuzcN0LiPSU3qOACK Nu2fgAnyVqftZDKbGOv+h4g2cquS8NosVb9sIloYyEFA2cQDMXfdFDIam3Bpo2W0 cPyisRpX2junjn8iChLP6EXWMhheCtuyMgu/He548PZBDPapSfxMoneFdhmpcBbW fXgEbotny1NoGkie/LpmqItxyYnE7240Gs+/z3pucFKvlqQhGCxyq81DgO4SuKlz 0Sne14FQQTvi8VlhXoJlZMSPhaa1PlDYnX55chiQMM+bFV9RiqEN+2YQlOsJj7pB HCPQN0rLlqPqLgJr/ZvQJnR3s0/djav/hFTA8eSXPjTk17kHvu60ORMC45kjshHR kYnnqyY+a8hizAAKHLjC5HxRn0QEkb1kxDJQjZ0DvHIO9XdWTlctsp59dFMQXu4S nBWN+Snp6bLrItUEOxjwgginMMuRI73i/MJ9Ao5TLmLi3urok1lsD+ZigG21BvJ7 Ftla8KvZWRUPnc9yWNF9v+6fmLh96kuoimbWzIUa5hRJ5PbkPSA= =3T4A -----END PGP SIGNATURE-----