-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 09 Jun 2020 13:29:14 +0200 Source: roundcube Architecture: source Version: 1.3.13+dfsg.1-1~deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@lists.alioth.debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 962123 962124 Changes: roundcube (1.3.13+dfsg.1-1~deb10u1) buster-security; urgency=high . * New security upstream release, with fixes for: - CVE-2020-13964: Cross-Site Scripting (XSS) vulnerability in template object 'username' (Closes: #962124) - CVE-2020-13965: Cross-Site Scripting (XSS) vulnerability via malicious XML messages (Closes: #962123) Checksums-Sha1: d78cecebbe15b6688099d37c25e4fae42d54e12c 2487 roundcube_1.3.13+dfsg.1-1~deb10u1.dsc 89a41f790a080416f5b2e28b0d526d0c38dd028b 2186060 roundcube_1.3.13+dfsg.1.orig.tar.xz 5376537824bf60fdd99e421ee44faac2fe91902c 3055184 roundcube_1.3.13+dfsg.1-1~deb10u1.debian.tar.xz 7e38e83bba381dc47c47791730a51c45742ea0e6 9350 roundcube_1.3.13+dfsg.1-1~deb10u1_amd64.buildinfo Checksums-Sha256: da214e3c61a5bd0eddb913927b5a713b755c44b28a0aa8841abf70ca48300896 2487 roundcube_1.3.13+dfsg.1-1~deb10u1.dsc b2493e8d4bcc6c741473a1395b096e07e120901c34581fce76f9d422eca79280 2186060 roundcube_1.3.13+dfsg.1.orig.tar.xz d8f020f6e32f09e878654e7bf2d0a742365a90d95b407596688b77e3da7db4b1 3055184 roundcube_1.3.13+dfsg.1-1~deb10u1.debian.tar.xz 59f488b877bbfa0fab4f0337cc34a4245559261b9b7b0e53f7e89b7ffe99b99a 9350 roundcube_1.3.13+dfsg.1-1~deb10u1_amd64.buildinfo Files: b30c24e7600dce9b52bf1bf66b87f1e7 2487 web optional roundcube_1.3.13+dfsg.1-1~deb10u1.dsc f3c8dca9029cf85cebad436f9339f1ec 2186060 web optional roundcube_1.3.13+dfsg.1.orig.tar.xz d42c150152ec6b7668b66b02ae7deeba 3055184 web optional roundcube_1.3.13+dfsg.1-1~deb10u1.debian.tar.xz af8788c058ee1f59736364e3a1858b78 9350 web optional roundcube_1.3.13+dfsg.1-1~deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAl7fc0oACgkQ05pJnDwh pVJ5IBAAmfhbruO6/pyOC//jFNhn43zO/2yUPzuG3i7FMMdPCSycZN1uVghpomhO N6vytrqzF8o5pO5nsHX+M4FYfdtQcn3SLbpntuoo1OQIO0IpmPQDkNq61KsRr12c gTe8YjsnKU0H3H3/qfhYAPlSw65QOuMmBU7QTVaDIkgBkTUOAS10922l+HxFe+37 /YzrvlqnvIVQaQW91WwvykYqMUTU37+kIX6W/i2Tw+4VRZ69iTSinp54RqgB606a Cdl23nDOQEdt9lzK5GS01SNIQ1F5k79UpKEm/JB8cZs6PgLVkvXIrfD5EJrKATeK p2nMsAq0mlo76OzkyrQ0FiDGDd1osxYFbie9GnqcfNPzy4gLqVz1NFIkFiFwdz/a FXM7qj1N+WuDVMECdGQ6s7znAAl9OFyaUZGX7vRcgbh+ZnlxY9u7PP3gSxwVpvgz +Ulm7wXItD108eet/RoSpE5siviFNzVyKfidZ+UnN88l8Y6BRVwVNh+SyhjmEY0J NwCIGUCq+AVCEi38wMNK+8FyTo3NHOmFAmbWzZCu7K0VmdHnqOtoeFJLxgesZGEI NoTr3VUncyqKGMTdjlZVALOpUvbjMtTi9l0kagZjmSMIC+t4nYQOXRCeOIweeXAd GAOmop/LF315Jjy6kbPrmm+1ViE8/EZf+oYqLYSsb09VmlcHFW4= =6ZcE -----END PGP SIGNATURE-----