-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 20 Oct 2023 13:06:45 +0200 Source: roundcube Architecture: source Version: 1.4.15+dfsg.1-1~deb11u1~bpo10+1 Distribution: buster-backports Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@alioth-lists.debian.net> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 1054079 Changes: roundcube (1.4.15+dfsg.1-1~deb11u1~bpo10+1) buster-backports; urgency=medium . * Rebuild for buster-backports. . roundcube (1.4.15+dfsg.1-1~deb11u1) bullseye-security; urgency=high . * New security/bugfix upstream release: + Fix CVE-2023-5631: Cross-site scripting (XSS) vulnerability in handling of SVG in HTML messages. (Closes: #1054079) * Salsa CI: Disable lintian and reprotest jobs. * Refresh patches. Checksums-Sha1: aec5c92120c23587ed03c013b755869d8bef8236 3305 roundcube_1.4.15+dfsg.1-1~deb11u1~bpo10+1.dsc c02ae5d485b3ffb2ce589a6e178801a619094be4 96916 roundcube_1.4.15+dfsg.1-1~deb11u1~bpo10+1.debian.tar.xz f001dfdcd6a95b769709bfadb6c13a60463cf4c0 14790 roundcube_1.4.15+dfsg.1-1~deb11u1~bpo10+1_amd64.buildinfo Checksums-Sha256: 961e50e2f1f9d2a1dddacd6909651483953699d50bbfaf98ef849659fdd69eda 3305 roundcube_1.4.15+dfsg.1-1~deb11u1~bpo10+1.dsc c5db806bbc7870357230d3385209530cd3242831515d246160f24602fd4a99dd 96916 roundcube_1.4.15+dfsg.1-1~deb11u1~bpo10+1.debian.tar.xz 2f05b25b5de81af8153a392f58ac269cde55b976c370afab525dcaa10ba94be8 14790 roundcube_1.4.15+dfsg.1-1~deb11u1~bpo10+1_amd64.buildinfo Files: 01e77a5692ea111f33e857eb0d9893ac 3305 web optional roundcube_1.4.15+dfsg.1-1~deb11u1~bpo10+1.dsc eaf42dccd6395ed3107a30cc354d57fd 96916 web optional roundcube_1.4.15+dfsg.1-1~deb11u1~bpo10+1.debian.tar.xz d9894bd5298bb64c8340ee5f2688abbf 14790 web optional roundcube_1.4.15+dfsg.1-1~deb11u1~bpo10+1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmU23UcACgkQ05pJnDwh pVKE4xAAgZKTXpqpovVH1pX9QqDKHj31GWL7JBG/3fxuOuKVbjGLA11CLzOkGzRR IweWg5ZNm2bTxy5z3C1vgi/ZFtOkXLqlA7zqLGF65igam8+UVHAsJhGsDc1Cxbjw /nAD8k10rU4NdlY5vti9ebVXXyo9I3NK35BHZpFBt622bqO7isr12y0bRAlqJEx3 0Ze97gnbca72ZyA9j9Grr9g5AjlnkJhk1tgkTVHP5YP0jvixBEX3AikibkFJ5K52 n3C4NB1qM5KFoAvkqgXBusJRZ905dNvZJ1uh9zj8n7yKNyzja5kO2v1c0A4kL2Fe At3PsRjCdqkb5VLee6JiZrUL9T4irXyfcqWsU8WAPd6e7n+zUhbgvyxox93oZFUK ucNr0dNYdCnJPxMT5vrEOJB57edPZWvbXSWsWzV1YKYSkb5/VvDGbqlc409zCJRH p70AtzV0Uj92OA5guA24yk7wSQo8Jf5n3A6gmGeidv5s/hgNcF2cHnb3YLN8UQtn E1JiuOPkOxoJjG3d78Luh91piQWGBIV09IFcJsqakT5Uzm5Y4D0sDqfnxRVqOa5N QfmOvjN8TrJY2q27Y2bdaGKcgcryRrBh2jz8sFHTTs1E09jOwKDjnwQJN7erqgdO eUPNTQu/Oph23hG/yr22tFYvml1Ut+2Fswc4zEXHbABlNhpmieQ= =PwYQ -----END PGP SIGNATURE-----