-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 24 Oct 2023 22:05:04 +0200 Source: roundcube Architecture: source Version: 1.3.17+dfsg.1-1~deb10u4 Distribution: buster-security Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@lists.alioth.debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 1054079 Changes: roundcube (1.3.17+dfsg.1-1~deb10u4) buster-security; urgency=high . * Fix CVE-2023-5631: Cross-site scripting (XSS) vulnerability in handling of SVG in HTML messages. (Closes: #1054079) * Salsa CI: Disable lintian, reprotest, and piuparts jobs. Checksums-Sha1: dbe44323d3b7a7826872386eda22b5ee7302138b 2487 roundcube_1.3.17+dfsg.1-1~deb10u4.dsc 9cf60a4eebd3c38934def45af1934fa4df0ec2e5 3056268 roundcube_1.3.17+dfsg.1-1~deb10u4.debian.tar.xz f490ea04adce81810458556ecd12bfa0964cc216 9429 roundcube_1.3.17+dfsg.1-1~deb10u4_amd64.buildinfo Checksums-Sha256: 1ece6d9c3c39da396a310ede8316ca1d1db0487f02bd69c217c78d7ce5464920 2487 roundcube_1.3.17+dfsg.1-1~deb10u4.dsc 12e5e1021a4680aa6cf08ebb28b12a13586b37da1914b46ddcbfac190dd7d4c7 3056268 roundcube_1.3.17+dfsg.1-1~deb10u4.debian.tar.xz 42b9492632763544507dcae937b8a2672b7e13aab309957bdb7156f0c9ef80b1 9429 roundcube_1.3.17+dfsg.1-1~deb10u4_amd64.buildinfo Files: 307b8d486586f6b3ebbbf459c2057755 2487 web optional roundcube_1.3.17+dfsg.1-1~deb10u4.dsc 23e1fb193974eb7601b4a32d33c0d434 3056268 web optional roundcube_1.3.17+dfsg.1-1~deb10u4.debian.tar.xz 5abc6beb3712459520324689ca1e01f3 9429 web optional roundcube_1.3.17+dfsg.1-1~deb10u4_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmU4JB8ACgkQ05pJnDwh pVKDHw/8DSUcR/6f5L2FL7DW3rNawzbHULLDgbdnzPbqEZFF36XTmsnimORId9dg pB89ef7tfsLFdPmwuvSmimf4w3VOdxbr7L+gxD24iryMovHogTnxHyi3D+DJyFTl SVZrwaizjqLkJYkUyTBDPpMzAiypM+RJYT9TTcy/gbOcwddK2yy2pAAIkKPSqaNC 4W5sIEwvBCWUyvai8sGgkJbzVX6O3SPrzv042/EejmZrS20cMYn2Fo1T9PcLFXG4 YaP8/oXOrUGKJHFPfSCyqF/kHNVfEbhtwQs16T8FqTE0S6NuMjOyo8gSdhLqZd8o OxTFM/8Mh0qKYpoiaAUzZvvtn/8N8d8ZVpEcHKaYbHHzIO2UFXxwWCt/fgeP83eT +e0zCSBnx2hvLr5okJ+bcxgyTDsaAlMEiMDr0F0qPOWTotSn5dGG2pW/GweqDuTf 2Jp3kHxABol3DegVrBg1aEmj9Zb/+DBvrjhqiiQF3uGWFk14O1Cka2cuEz7tIPbj DyzBPHCfAfkxH652S1MAxpgCuIYHYLUsjSaH5+N382aOpuhWoRep1XxXSRW9cq9F B1rz9iX66Zh3QCj7sY1N+9Z37PwAXvsYGNm59t/hz7cyu9QL/kPvvG/T1f6FqdWA NcxrqOwnco1Tzjwyxi1BVN9QHmv39yrqf3CK5VYobejxUX3MicQ= =lA6C -----END PGP SIGNATURE-----