-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 04 Dec 2023 17:50:05 +0100 Source: roundcube Architecture: source Version: 1.3.17+dfsg.1-1~deb10u5 Distribution: buster-security Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@lists.alioth.debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 1055421 Changes: roundcube (1.3.17+dfsg.1-1~deb10u5) buster-security; urgency=high . * Fix CVE-2023-47272: Cross-site scripting (XSS) vulnerability in setting Content-Type/Content-Disposition for attachment preview/download. (Closes: #1055421) Checksums-Sha1: a876b8795afc55a2a800bfeade3023a1a13e123e 2487 roundcube_1.3.17+dfsg.1-1~deb10u5.dsc 73adaf0953cf216b87a04207df2039196fed04f9 3059172 roundcube_1.3.17+dfsg.1-1~deb10u5.debian.tar.xz 06750b232e40454a55ba2fb37eb61d5d7c5e2d59 9429 roundcube_1.3.17+dfsg.1-1~deb10u5_amd64.buildinfo Checksums-Sha256: c62885c062ac7851e0b741b711f86f0808421d6599829f4af0952351bffded8b 2487 roundcube_1.3.17+dfsg.1-1~deb10u5.dsc ee5b9996bb688dc95c1effb7593c3692bae8fc940195c125d84823e893044e51 3059172 roundcube_1.3.17+dfsg.1-1~deb10u5.debian.tar.xz 3784d08c507f3abc61f47cd7a11564ec86d943ff57b45cf2b883ae921ee7c2ff 9429 roundcube_1.3.17+dfsg.1-1~deb10u5_amd64.buildinfo Files: c0f92d32fb76fa323138f8a4e999d145 2487 web optional roundcube_1.3.17+dfsg.1-1~deb10u5.dsc 6ceef8ce73d29f5e1fec047025f31a00 3059172 web optional roundcube_1.3.17+dfsg.1-1~deb10u5.debian.tar.xz 976a2b76870436d3e2e8cdc6efa4b8df 9429 web optional roundcube_1.3.17+dfsg.1-1~deb10u5_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmVuCJwACgkQ05pJnDwh pVIYlw/8CC86ESwDuH+8hEPC0490KXCU8nD7tefvHISR/ec7dwZ8Wkn5vJ4vuqBI pn8MGYgewHZ7NRNh+E/Zr8CZ7E/FUFic0JAUd3ImAErc2kmXCFGYVdSZFzRaF+i9 +2jB8aLZyyS00NqnhnYFrRCcjRj3OMXurQSTdS4gqGh397iWqLSUJZwGRPbq/Gm+ Cb0WOG36NvIdv5Asr+UVp6XZ6u81PUsxPkq6BqWrUxGWS9kqypbSugjnGsE80tCq xpZaZ8iaIlXG5pFs19oOJ/5ySHRbjKcN4kgk+TncmWBC9FKWVkIWSj8Ez8jk9DGL q4Lhsmhx5tPvIpKkO5hiaJ2QcZ3RI0RbOY8r4N55kKY77PyV1sjI9VZ+UptHgdSk XXuZGUKb0Qa+RF7M1Hkt5qupgLWB3qyihqAq+c2+sm4K1QsmdSXoUmrQfPUdl7iA 1V9FW7vBfJVEZ/Ynx7KXegjKglt/5oGum5OjRAjmWPRupZpCGAvPSdejy90lNf6o dNa3ktW6e0sae4Kt0e2zuaLBfK2xdI7BMgS6JIRmeK8RIg48IGqS0eraJucC7pDh Aa4QSCro3M2M9FJD2d+zntyyJFysMpW1r+6v2BmBBnJt2PRp8+zpCLw1hOKa6hni e/F6JMcTQxYmoLCjxsjTA2kHC8d2SNE3yT8r7mOBCdbPXH7S98k= =mPh8 -----END PGP SIGNATURE-----