-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 28 Nov 2023 15:49:21 +0100 Source: roundcube Architecture: source Version: 1.4.15+dfsg.1-1~deb11u2 Distribution: bullseye-security Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@alioth-lists.debian.net> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 1055421 Changes: roundcube (1.4.15+dfsg.1-1~deb11u2) bullseye-security; urgency=high . * Fix CVE-2023-47272: Cross-site scripting (XSS) vulnerability in setting Content-Type/Content-Disposition for attachment preview/download. (Closes: #1055421) Checksums-Sha1: 0835cda737e9d03e9d9fef98bdf026da8dd895ba 3273 roundcube_1.4.15+dfsg.1-1~deb11u2.dsc d6fd19bdf02740d5658892394ab6a37b8b0f16ff 98008 roundcube_1.4.15+dfsg.1-1~deb11u2.debian.tar.xz b45af3f0a1717e22bd5f29104dc978b3e94ede2f 10829 roundcube_1.4.15+dfsg.1-1~deb11u2_amd64.buildinfo Checksums-Sha256: c92c05b483483696ec7e43bec74daa2cf9f698d5d587aff8c02a9b626406aaf3 3273 roundcube_1.4.15+dfsg.1-1~deb11u2.dsc 0b671c3d3219d3637ff6d5d6348ff4ab4429d78255f9435f4781b1fceb103206 98008 roundcube_1.4.15+dfsg.1-1~deb11u2.debian.tar.xz f0cc8ef762e8544b6fbea8fedf577d7729269916d9f4f73065e93fb042f1520a 10829 roundcube_1.4.15+dfsg.1-1~deb11u2_amd64.buildinfo Files: dd17b893c3ac36ff38a5a891b82f1a26 3273 web optional roundcube_1.4.15+dfsg.1-1~deb11u2.dsc a9915808e6ff6c611d565a34d433a3f5 98008 web optional roundcube_1.4.15+dfsg.1-1~deb11u2.debian.tar.xz 58f07c7f7514db1bdfd4282580515498 10829 web optional roundcube_1.4.15+dfsg.1-1~deb11u2_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmVmAkcACgkQ05pJnDwh pVJaRg/9F5kxr8mmBau1MLUud/23/KdnaB9Tha1UHWVi1C3DFmIKSSEQdmoIPD8z m9knBtzbsJdmfJL9Tqo6E0FxRavMRhTCA9WlJc1DJ+gYRiQ3XzMTDf4Nre4I9mxd r86UlgJDLF+FRvBKCFuO0QA6YdoxDOj5LbUNvJfO9OxQr2SarI9pDkuPumDLyMvh rLZJTcd4dEp9UC70e3rKJ4abNf9C7xn/rG+SHDlbDYGAoQs8I6g+jK6E6yX6O/AU CXZulVWpU/MtnDH3vMS+17BXcS4zcoW6XAusg7Y+M8XeIY+HBdAoSA/4zUKGRuvW cStB2pajJ4U/kXPx2C2oL+vLKCUXEDBBD+DtIjury11qGCpYLy29HJblpaAyuEGu lAePN6s859vZq3jmDUjsQs6ao4RuyC9cYIYM9JaVMwvSEM+An07i5hvYNvwApY/X wTmnq6+GJFm680b62o/zpo5d59I7S0YWweTzJDYRPL1p+X9g2WZqy0245mM+6COc HnztCrg7xj2rqCj73fig47L1M20Wlr29Ic0eDYc95WsZHeO221FPjbN69gKk6t2g aMdVFn1N9euS6bct37Z/3ZCeWagC0maLvDXWe3VhH81RNJzQxX874DFAmfbN9/xQ ykDEijBNprVpmTQNJbMiu757VpX6Deb1KurG80cXJnF9m46F1AM= =eSQt -----END PGP SIGNATURE-----