-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 08 Dec 2016 19:53:32 +0100 Source: roundcube Binary: roundcube-core roundcube roundcube-mysql roundcube-pgsql roundcube-plugins Architecture: source all Version: 0.7.2-9+deb7u5 Distribution: wheezy-security Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@lists.alioth.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: roundcube - skinnable AJAX based webmail solution for IMAP servers - metapack roundcube-core - skinnable AJAX based webmail solution for IMAP servers roundcube-mysql - metapackage providing MySQL dependencies for RoundCube roundcube-pgsql - metapackage providing PostgreSQL dependencies for RoundCube roundcube-plugins - skinnable AJAX based webmail solution for IMAP servers - plugins Closes: 847287 Changes: roundcube (0.7.2-9+deb7u5) wheezy-security; urgency=high . * Fix vulnerability where a remote user can execute arbitrary commands due to lack of sanitisation of PHP's "mail" function. (Closes: #847287) Checksums-Sha1: 2158dc711493e4f1eb02f5a94f555bf9e9ccd394 2244 roundcube_0.7.2-9+deb7u5.dsc 81f3e5057c7bd2175318cfc261615c032afa4235 2197455 roundcube_0.7.2.orig.tar.gz 2e3d6cb248f8c2d897d2bdc318af56342cc699b3 63384 roundcube_0.7.2-9+deb7u5.debian.tar.gz cad465317476130ccfb141887ac7039263635a0d 1027172 roundcube-core_0.7.2-9+deb7u5_all.deb 9e6690b21a638cc9eac584756a870828206e637f 28936 roundcube_0.7.2-9+deb7u5_all.deb 7e1cc8f6c5aba106e06149bf39ac8ac718849677 28868 roundcube-mysql_0.7.2-9+deb7u5_all.deb 9e08b2bba735c83e1069b2b3ac7cac36f47767d4 28858 roundcube-pgsql_0.7.2-9+deb7u5_all.deb 5494e88f37f860705d50e8bfce8bd13aee1a9e4e 324256 roundcube-plugins_0.7.2-9+deb7u5_all.deb Checksums-Sha256: c99df957a4032fa6d89c1b7c8bbf32a507533733bc40626cafdd8df6e240d516 2244 roundcube_0.7.2-9+deb7u5.dsc e14955243b5c31317c3cfd568579399819aefa659e051735b67fceda784331e2 2197455 roundcube_0.7.2.orig.tar.gz e218324f5f7a1d6767ce27d34f52bd5faa13d55908d1a58a33803b2beab40160 63384 roundcube_0.7.2-9+deb7u5.debian.tar.gz 0c980411a62ad1b3c4f6c061d2f23b755e49a7845aa0e324c6e4e1d38bd24ccd 1027172 roundcube-core_0.7.2-9+deb7u5_all.deb 4eb4d2980c59a8df2c5e4cc809d94f3ded8c0985310d1eb732a90f30a8200922 28936 roundcube_0.7.2-9+deb7u5_all.deb ff7080d0493d3fd60d2295cf7d078e4fe5192c182551687b55922346f87d9329 28868 roundcube-mysql_0.7.2-9+deb7u5_all.deb fd7ce7e483bba384125999564e3d7ee2a1272a89667a70bdc444166f0d22b20e 28858 roundcube-pgsql_0.7.2-9+deb7u5_all.deb 94fe78e125ea9074d1fe72db41f868b7dd2c0d44c808564d06153074b7918bbe 324256 roundcube-plugins_0.7.2-9+deb7u5_all.deb Files: 40d5f066de4a3600964ba5abf0d97fa5 2244 web extra roundcube_0.7.2-9+deb7u5.dsc 2b77fe823de00a7ebd85b8919e40d78d 2197455 web extra roundcube_0.7.2.orig.tar.gz aaf6a3866d61b3ece908f6f893982f42 63384 web extra roundcube_0.7.2-9+deb7u5.debian.tar.gz c459a74bd7463773f0262aa54af1400c 1027172 web extra roundcube-core_0.7.2-9+deb7u5_all.deb aa280c59b9575a9b9de6add6c5270574 28936 web extra roundcube_0.7.2-9+deb7u5_all.deb 131278526bb6d45fef13ff2712ba3c10 28868 web extra roundcube-mysql_0.7.2-9+deb7u5_all.deb b39a529356f17a2ccbd2703123554b90 28858 web extra roundcube-pgsql_0.7.2-9+deb7u5_all.deb 7e6243bf4a8d23dbff31705ac10d771a 324256 web extra roundcube-plugins_0.7.2-9+deb7u5_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAlhJrdIACgkQHpU+J9Qx HljqWhAAnVF44jpGwRULyf/c4q5R2MvOGiIJInQO08TqXBF1236F0NZ3RfzEMfbx ppFMa930I3z/CIUlSntSpOfmtpTL9a2Szgbyr4SIj571yMrhNQUiHH5A38ZxzfpR NJGIae+t6b1roAqiUCIfXi/Ei4fWmEL/6QFtEeyLBDbtdtmDbjswHiH4O1trobGP OpOhI4rhqAVcoBfNA3X4EtqOS1g0iCAp9BqcbvgoHwv0ra+nLvzvKi2SbKTfzBxW uOBeQ98a7BlkXQGnqPCUo37KpL0Pow1K43uKI11SmszrVwj3gNyKMla1UUSF4SIJ w8bMVdzdHcxBsG2b5Jldag5NM251kXpFT8rIqQpxwZvEHpr5IdaDTrY+qOtkzeCu /+g8Pe82uHVLiHClkQXHXeJ3AYgUsW0BuIdvuZjqTVrLSKtcMonyDE5lrrIDrReo LKnZQS0g29C9Su6sPmQ68XjBhy1va+ZTX59fPsLUVhXPZnj3bSE/bc3YmGaKq8Th YxEspMyvQUIXoLwqDFPYsrsqqa9zf4wuybLqo+Dxdw6gcb9BsYDnfMUe2mFgapN7 FLJbuPF9taj0SNeLCAqTkEBhksxQUuI9JKFtWYAnug8/TBzpt8qgRXC97qnDuVOg /+aMyCkGLtPkoY+NuZGHxxE+7teRtSVSgSBI9Dto5o6tHA6qEcE= =W3+J -----END PGP SIGNATURE-----