-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 25 Sep 2023 14:22:10 +0200 Source: roundcube Architecture: source Version: 1.6.3+dfsg-1~deb12u1 Distribution: bookworm Urgency: medium Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@alioth-lists.debian.net> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 1030161 1033468 1040705 1043395 1050317 1052059 Changes: roundcube (1.6.3+dfsg-1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. * Salsa CI: Set RELEASE=bookworm. * d/gbp.conf: Set --debian-branch=debian/bookworm. . roundcube (1.6.3+dfsg-1) unstable; urgency=medium . * New upstream security and bugfix release: + Fix CVE-2023-43770: cross-site scripting (XSS) vulnerability in handling of linkrefs in plain text messages. (Closes: #1052059) + Fix regression that broke use_secure_urls feature hence OAuth2 authentication. (Closes: #1050317) + Fix regression where LDAP addressbook 'filter' option was ignored. + Fix regression in decoding mail parts FETCHed from IMAP. + Fix PHP8 warnings. * roundcube-core.cron: Trigger gc twice every hour. (Closes: #1043395) * Fix GuzzleHttp autoload location. (Closes: #1040705) * d/p/fix-autoload-location.patch: Set ‘Forwarded: not-needed’ DEP-3 header. * Refresh d/patches. . roundcube (1.6.2+dfsg-1) unstable; urgency=medium . [ Amin Bandali ] * Test suite: Adjust short date test to make it work with all ICUs. (Closes: #1030161) . [ Remus-Gabriel Chelu ] * Add Romanian debconf templates translation. (Closes: #1033468) . [ Guilhem Moulin ] * New upstream bugfix release. * d/gbp.conf, d/README.source: Remove obsolete comment. * d/sql/mysql/1.3.0-1: Move inline comment. * d/p/fix-short-date-test-icu72.patch: Remove patch applied upstream. * Refresh patches. Checksums-Sha1: edf1a65923b75016ecc038a1c28a54ade8b050ff 3833 roundcube_1.6.3+dfsg-1~deb12u1.dsc 7c23d146a7711966e64c34da388f4f8619b6189d 104888 roundcube_1.6.3+dfsg-1~deb12u1.debian.tar.xz 230048ba6a2eede6b52be89cded126d4c66b53e8 13892 roundcube_1.6.3+dfsg-1~deb12u1_amd64.buildinfo Checksums-Sha256: b995a9617183eebb218dd8f57f3a7d84255ef727ffa2ee6252305fae99a61126 3833 roundcube_1.6.3+dfsg-1~deb12u1.dsc 0a50e63170f69597832cd420d435a20af53696bbee304de77e1d74b5c617657b 104888 roundcube_1.6.3+dfsg-1~deb12u1.debian.tar.xz fdbc65e3550c10e16fcfc50e9b10e10802b43b3bd130ac5499e433d36234d031 13892 roundcube_1.6.3+dfsg-1~deb12u1_amd64.buildinfo Files: 371da518c922b39658a7dca7becaa1a7 3833 web optional roundcube_1.6.3+dfsg-1~deb12u1.dsc 34565c12a0d199b7e36b92252ffeae17 104888 web optional roundcube_1.6.3+dfsg-1~deb12u1.debian.tar.xz 6aa3158db5908eacc6b2fbf381217404 13892 web optional roundcube_1.6.3+dfsg-1~deb12u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmURfXEACgkQ05pJnDwh pVLFOxAAq/inAIsR+/PQp6YzSpOCBGEnRBqPbnxtbjshUDsHfTxi4Lg29RdsexA9 aDR9C5cUnf3Y/zI+1iD6STmk/slnxR3qOnijigWUevWmXQ5SB0lWLH0BGzNrm6P9 GVKWBp9YnZiOGLeiH8pTGdGZmK8WsZD2hG23O79ah1ukVXReyunY5ifklujZkQ1x rmo+DY5ct+FOgpJTl5k2/wxAIv15Eg1Ke4xErsR6MrwcMBNukDew3BRQpELLM6TF oDumyO5ggLhuAeDP4Ke5Vj7ku7x1jHnJ6ykE5V0COPfy4ksYUdrglMjaG7F5rodS YMl3HGEStNB7yzEv/CaMevqNg8vcsB/zqG2POBMIp6bsVPjAvXgSGya3LqgwxJqg 0/+7RFUKLPWrjBvc0qi4ztLubo2mvWoUqPWV2d159WV7fvmFFwCyzQLrA/Rwi2ng /x3jUxE7xim2glYG/CO6aK3aldFC982BbtMU3Qnu3cq4lSmz3Zjr7SQU06SK2xXo WvnShpJHEUq77R3lz6he0Hz/AKK9IfLNDD4aK4a5UKVIlsURSxxWTnXSrjcg8wzA Iy44b8TOFv4eFPh1dBQoUQIbY7IaM5ck6Fh+Ff1rDJFQLFn94/ompZw+H/Fy94zP D7Dp+uSlq3S8/tVr5IH6hPvMrZY+QEProvyl+qrSf1gY1Mkb7ZI= =KN/c -----END PGP SIGNATURE-----