-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Mar 2026 09:54:58 +0200 Source: roundcube Architecture: source Version: 1.6.15+dfsg-1 Distribution: unstable Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@alioth-lists.debian.net> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 1132268 Changes: roundcube (1.6.15+dfsg-1) unstable; urgency=high . * New upstream security and bugfix release (closes: #1132268). + Fix SVG animate FUNCIRI attribute bypass (remote image loading via fill/filter/stroke). + Fix regression where mail search would fail on non-ascii search criteria. + Fix regression where some data url images could get ignored/lost. * Refresh d/patches and remove those applied upstream. * d/control: Add Build-Depends: node-source-map. * Improve custom patch to avoid dependency on mlocati/ip-lib: + Trim leading zeros from the decimal representation of IPv4 octets to match GuzzleHTTP's mangling of invalid IP addresses. + Treat IPv4-mapped and IPv4-compatible addresses as belonging to the local range when the v4 address is also local. Checksums-Sha1: 89812af8bf73f73b312dcd83fdaff7fb9f70e22d 3845 roundcube_1.6.15+dfsg-1.dsc 0cffaaa8522bb9496ff3ec1aad1b9d17f1e7edd7 126856 roundcube_1.6.15+dfsg.orig-tinymce-langs.tar.xz 7c3866251bfef08a39b1459b05fb2e99b177a786 1928608 roundcube_1.6.15+dfsg.orig-tinymce.tar.xz ed576296b8b4da4e49f384344934fb2c6ed4a5dd 2793028 roundcube_1.6.15+dfsg.orig.tar.xz 5619fcdfb5b17aa6e07d6ca6ba60bee728bce909 156808 roundcube_1.6.15+dfsg-1.debian.tar.xz ee561d53e8c92a78f7d43179cf7eab4eb3542f65 6222 roundcube_1.6.15+dfsg-1_source.buildinfo Checksums-Sha256: b750836f8f47d33313343d5618e2da1158bbc2c78c640db91b2649214a20ad6f 3845 roundcube_1.6.15+dfsg-1.dsc f3d8c7e7137dad314b7acff2b80649ea036c4532f3b1194bd39c163d6884416c 126856 roundcube_1.6.15+dfsg.orig-tinymce-langs.tar.xz 3040064c9e504486506dc597f3eeec0a79a31278e06d0d15b7c0568938124b0c 1928608 roundcube_1.6.15+dfsg.orig-tinymce.tar.xz b23845f78b4bf5460821d1449f22f2069fa53ccbcc9ed918068549bbc1b651fb 2793028 roundcube_1.6.15+dfsg.orig.tar.xz d52399e01df9f832c3c665889e7af4dfc5bb021a88d93d464484b22c3475fbb5 156808 roundcube_1.6.15+dfsg-1.debian.tar.xz 4137f4bec050a1fb6efea12175482c27a2e412b548339b535417e24145b2afa5 6222 roundcube_1.6.15+dfsg-1_source.buildinfo Files: d619cf1c80cb906246a99a3c916fb932 3845 web optional roundcube_1.6.15+dfsg-1.dsc 916486a39ee15f3bd2d10c9472af340c 126856 web optional roundcube_1.6.15+dfsg.orig-tinymce-langs.tar.xz 9b7a65d3a402cfbad01a3144b59da634 1928608 web optional roundcube_1.6.15+dfsg.orig-tinymce.tar.xz 1eca96bad2b14b928e4e62390fd7d3f9 2793028 web optional roundcube_1.6.15+dfsg.orig.tar.xz f24e472bcdf30b191189aaf9ea9e6cd1 156808 web optional roundcube_1.6.15+dfsg-1.debian.tar.xz 8aba2564793ad94b677ac3d138e116ea 6222 web optional roundcube_1.6.15+dfsg-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmnKW5gACgkQ05pJnDwh pVIGixAAh0tgLfzJwlhmkpDG65lvgaGKsmiijXRT5aW7CxWiCse6GMpu4JxjfVtB 6qmpO5oePV5Q6elCInq0LaZSR7aZyQLaH7tzEUv6TCUDRQi2dWj1mlGqMgsFCOxY ERSio8rS/8Iyb0TrEMYiFH59OB8BYvsrYcJE8pk/4SV8YdWSpm1VNNTqe/lA5veP js9RhIGcuBhTqO1sxLpXVnrMGaqFqojZJvpoHfhHPb9lw1NuZ4qyv0WuZ3N/5xNZ 0+dAp/EQySTrhrtnsJnN9AHKWoXFd3kbWtHXD3rNFmHkuI+4eaBeqF7oHLacJr71 ugV8Lvoj3fkfHYlxITIa+NBCoNAfqvn7E3fXGkMb33ahPcHQZVFxRQAlLkMvZVWk +eHxvc2Tb7hemqH4gIeu4zE+s4cA55cogObiN0o64nOKT3RtWKtjzs4fwkIhqYnW hLImfH8L1hvnErlWLfAcW30E7DvmGmseXYCpa8DgXGq/wPaMtRUHM6+IXkz684Om OYLKiRw4OAclfAeGh1kS7TDWRU7jce5gIJh+WHRHEG99Ze3dGvDQv7GNtTX5Q3Uk M2zQuhlts908abwKOxCro2UotrBSEGf+UQiDee414T3z1PDI3ercdZdfT9zBvPup I3zxSUqm3J8qNcGQ8m/cryFeMluauhfp/HIwwm02DDsTYCXDeVs= =eoLB -----END PGP SIGNATURE-----