-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 14 Mar 2017 11:59:40 +0100 Source: roundcube Binary: roundcube-core roundcube roundcube-mysql roundcube-pgsql roundcube-sqlite3 roundcube-plugins Architecture: source all Version: 1.1.5+dfsg.1-1~bpo8+4 Distribution: jessie-backports Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@lists.alioth.debian.org> Changed-By: Guilhem Moulin <guilhem@guilhem.org> Description: roundcube - skinnable AJAX based webmail solution for IMAP servers - metapack roundcube-core - skinnable AJAX based webmail solution for IMAP servers roundcube-mysql - metapackage providing MySQL dependencies for RoundCube roundcube-pgsql - metapackage providing PostgreSQL dependencies for RoundCube roundcube-plugins - skinnable AJAX based webmail solution for IMAP servers - plugins roundcube-sqlite3 - metapackage providing SQLite dependencies for RoundCube Closes: 857473 Changes: roundcube (1.1.5+dfsg.1-1~bpo8+4) jessie-backports; urgency=high . * Backport fix for CVE-2015-5381: rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element. (Closes: #857473). In 1.1.5+dfsg.1-1~bpo8+3 the patch wasn't added to debian/patches/series. Checksums-Sha1: 0425fc59e0fa6b04013865b4a29d6cccd284ac2a 2501 roundcube_1.1.5+dfsg.1-1~bpo8+4.dsc 282b42ed7884f5091cde89cfd8637a78f055bd56 1770016 roundcube_1.1.5+dfsg.1-1~bpo8+4.debian.tar.xz ebbac500b9735a689482bc69d5740b96b320f966 1928590 roundcube-core_1.1.5+dfsg.1-1~bpo8+4_all.deb 27b604e595a1fd1b413a74f47b6f3c7e6b8fe044 1458 roundcube_1.1.5+dfsg.1-1~bpo8+4_all.deb 11e786e811e220a8f205f32e4414f18d412f86d3 67378 roundcube-mysql_1.1.5+dfsg.1-1~bpo8+4_all.deb 65ad3c4d57565b46c80fc3887cec2698aaf20882 67360 roundcube-pgsql_1.1.5+dfsg.1-1~bpo8+4_all.deb 31d0f570965b2414730d7fa21b0aa54aaa9030d8 67346 roundcube-sqlite3_1.1.5+dfsg.1-1~bpo8+4_all.deb 97efdc55218cdfcb737534b8eac7e1c58d1cbce7 583612 roundcube-plugins_1.1.5+dfsg.1-1~bpo8+4_all.deb Checksums-Sha256: bcd5f5131813ee5ce2a5b668210ae7088db1400c12045b42b397448ea58fefa1 2501 roundcube_1.1.5+dfsg.1-1~bpo8+4.dsc 91c23f19b9400ff010a4f28c6251d16831fe0a630584654c8997dc6f7c1c5aeb 1770016 roundcube_1.1.5+dfsg.1-1~bpo8+4.debian.tar.xz 211b90f6edfc7ca9d1905fd1f796c45ae9332581c3190a9a0c086092300821ab 1928590 roundcube-core_1.1.5+dfsg.1-1~bpo8+4_all.deb 9d62b3b6447628d521446bab515c131cfda9c9738567160a00f722c8c428aec3 1458 roundcube_1.1.5+dfsg.1-1~bpo8+4_all.deb 5f7bd5cfda88c5713fce8b60a1efa15145b99d58680c21d3aacc5d6a8d67589b 67378 roundcube-mysql_1.1.5+dfsg.1-1~bpo8+4_all.deb 9b1303961cf2ec043643a8d495e4a822b14981e496f81d404ce6419277072919 67360 roundcube-pgsql_1.1.5+dfsg.1-1~bpo8+4_all.deb bc34836678e0ef21a44fa31935ac9b51b4814d256c4931142e5bbd0f4fce3a01 67346 roundcube-sqlite3_1.1.5+dfsg.1-1~bpo8+4_all.deb c41d1f493eb1373426798b09c715ab071932a0910cc9c4455648588a550b35cd 583612 roundcube-plugins_1.1.5+dfsg.1-1~bpo8+4_all.deb Files: 3123308413e2b581eaea91b674d75321 2501 web extra roundcube_1.1.5+dfsg.1-1~bpo8+4.dsc 9541afb4581b7e248d1cf10ba78e3f30 1770016 web extra roundcube_1.1.5+dfsg.1-1~bpo8+4.debian.tar.xz 8ce00c9eb12847f7d7ef7ecbf058fcd1 1928590 web extra roundcube-core_1.1.5+dfsg.1-1~bpo8+4_all.deb 56fdef6c5d9655e46f70bea163aed4ce 1458 web extra roundcube_1.1.5+dfsg.1-1~bpo8+4_all.deb afbe93e857911918e1c6d227fac1b08b 67378 web extra roundcube-mysql_1.1.5+dfsg.1-1~bpo8+4_all.deb 7b37b472c264f2b072a99cd1daa2e259 67360 web extra roundcube-pgsql_1.1.5+dfsg.1-1~bpo8+4_all.deb b0b0c7cfba63bb3646443d2ea7616615 67346 web extra roundcube-sqlite3_1.1.5+dfsg.1-1~bpo8+4_all.deb 6d266b26302008dec23e6040c72e90f7 583612 web extra roundcube-plugins_1.1.5+dfsg.1-1~bpo8+4_all.deb -----BEGIN PGP SIGNATURE----- iQJEBAEBCAAuFiEErvI0h2bzccaJpzYAlaQv6DU1JfkFAljH2eIQHGJlcm5hdEBs dWZmeS5jeAAKCRCVpC/oNTUl+QMMEACenGg9X24oK/h4mVE/HyVMbd4lhPBxiE1k +lzRjzgfUmd3i+tITvivt3xnac1XtHDc0v8/4deDWNPHMpfN5R+fMF2MRFfB55Kd pk/lX5p2k6qs+l+4z8+do5uMtRsGMubwClt0zd1bdFG0tNobKNBZIwZHwenSuP98 IdWN+hGFGQqCTJGcni8xcF6EUbTUvft6d0f54HIDG1a2SwRCf1QdBJWXbn833sdp 5rYDUbBasUtGruu4n57k+beMJeDxau5v1JVGtF3jEGxjMM+nPEdWkTmGXyqtArGF iZWz7CS/F0YXlBnsQY0buuyLm0tXx1KWFGbNTCLaVwjygGA4QiN+nISRG+vN3Od3 MgU0xXoGrV9FSONDMIxi4bfN1qzY7VHLVcBA+B1DClDzZ3c3hdpliCjGnMvb8QxH H5vIMsIb+K+CV3G3Tz/9vm1X9ABt5aROh/W0OMALf5dY827CpT2hDHQjnp8BgKFs 4FX70R4sO2PZpdW+l2Ic2CUHDESj9z/AZfx6i3ZDDCgJfnMQDRFjVBisUMuVvnOv sUyVxfG6Y1fjdvrlkfFGLzoE8VwI2shz/OQqJzjrGVp7Mru0xY+4ld9g/u6biGlS yKYQBYDzPpD0xHPqkBp4Fk+D9V8O7zPKK0RiLf6jXcZjPvd8dWEyB2mQdmw06i13 GELh0vvSGA== =LgV8 -----END PGP SIGNATURE-----