-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 09 Nov 2017 06:45:05 +0100 Source: roundcube Binary: roundcube-core roundcube roundcube-mysql roundcube-pgsql roundcube-sqlite3 roundcube-plugins Architecture: source all Version: 1.2.3+dfsg.1-4+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintainers@lists.alioth.debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Description: roundcube - skinnable AJAX based webmail solution for IMAP servers - metapack roundcube-core - skinnable AJAX based webmail solution for IMAP servers roundcube-mysql - metapackage providing MySQL dependencies for RoundCube roundcube-pgsql - metapackage providing PostgreSQL dependencies for RoundCube roundcube-plugins - skinnable AJAX based webmail solution for IMAP servers - plugins roundcube-sqlite3 - metapackage providing SQLite dependencies for RoundCube Changes: roundcube (1.2.3+dfsg.1-4+deb9u1) stretch-security; urgency=high . * Backport fix for CVE-2017-16651: File disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default. https://github.com/roundcube/roundcubemail/issues/6026 Checksums-Sha1: 11017a68091d71411530edfb165d36c4cb82f1ef 2472 roundcube_1.2.3+dfsg.1-4+deb9u1.dsc 46e0444f23e53269e3db43797005400d3a447b06 3350260 roundcube_1.2.3+dfsg.1.orig.tar.gz 402fbf6e4fe097befa3e8a99e2a2f42e483aa979 4443752 roundcube_1.2.3+dfsg.1-4+deb9u1.debian.tar.xz f090f6b251e80ce3171dddf9c7a1142d93626e3a 2112570 roundcube-core_1.2.3+dfsg.1-4+deb9u1_all.deb 57f9524dab98a232da9041b490754b7cf8bb1e0d 70912 roundcube-mysql_1.2.3+dfsg.1-4+deb9u1_all.deb 1c1b1b37ea02a4c2ef4190c08b00f9018760dd09 70888 roundcube-pgsql_1.2.3+dfsg.1-4+deb9u1_all.deb 4ae93d87b10d57cc66a4d0e7b3b9e8ac81d1339d 661448 roundcube-plugins_1.2.3+dfsg.1-4+deb9u1_all.deb 6c7d631136e77a3137d343e220d6842b2e5971aa 70864 roundcube-sqlite3_1.2.3+dfsg.1-4+deb9u1_all.deb b102180dec73f433521d530a167c31ada1ff6676 1380 roundcube_1.2.3+dfsg.1-4+deb9u1_all.deb c6dc190acb14d69f57d4950164779146ad6277da 9219 roundcube_1.2.3+dfsg.1-4+deb9u1_amd64.buildinfo Checksums-Sha256: 0e6435f5eec86ea8f52a01274d309a91af05ec48d4ce1c9b3dd79589bae65a04 2472 roundcube_1.2.3+dfsg.1-4+deb9u1.dsc f3c4b66ee33edc92025e3fad003ea9cf92f2577b5a0ca6acfd5168d67abd6a20 3350260 roundcube_1.2.3+dfsg.1.orig.tar.gz f21a09772edd2e106085c90f306f4d935f0cca792fa26122b818ef1782f55b72 4443752 roundcube_1.2.3+dfsg.1-4+deb9u1.debian.tar.xz 85d514743c46f1f8e8fff9311b23b92ecd079324bdb20f0a6f9c2881e4a1e68d 2112570 roundcube-core_1.2.3+dfsg.1-4+deb9u1_all.deb 7779b356c72991e20bde552637048151587351508343f4e6245f131b3e9d561f 70912 roundcube-mysql_1.2.3+dfsg.1-4+deb9u1_all.deb 6be2a4eb9d12a89f9ce5f4ffe83af48100063ec4ebbeda0b0d60347db5824a58 70888 roundcube-pgsql_1.2.3+dfsg.1-4+deb9u1_all.deb 6ca1a881bc8dc736ff2f6ed62a0c69bb3c45a848ea952af7eb327fb034ea8e25 661448 roundcube-plugins_1.2.3+dfsg.1-4+deb9u1_all.deb 8a824e5652538acfce5c5789a1b3e0e7d115e5f573726c308dc5a9c7e6634090 70864 roundcube-sqlite3_1.2.3+dfsg.1-4+deb9u1_all.deb dc32f67590b7433954787d237850dcc52632ad2d52fe1a48eb84efa2dcb0db46 1380 roundcube_1.2.3+dfsg.1-4+deb9u1_all.deb a9cf6a694c75e75ada0c0c0ee71b6179c54a327c17086315e917d0ccd5857384 9219 roundcube_1.2.3+dfsg.1-4+deb9u1_amd64.buildinfo Files: 2d7137dabf8b490c4f2b104e77603193 2472 web extra roundcube_1.2.3+dfsg.1-4+deb9u1.dsc 1fc2fd165ffa1a5baf73c992058cb1ea 3350260 web extra roundcube_1.2.3+dfsg.1.orig.tar.gz c3fc24a01874a5c8ebb38cb1235ceb49 4443752 web extra roundcube_1.2.3+dfsg.1-4+deb9u1.debian.tar.xz 353360c286a4740c41c751e615426c68 2112570 web extra roundcube-core_1.2.3+dfsg.1-4+deb9u1_all.deb d49e78787ae3180bc073f1f70d623b02 70912 web extra roundcube-mysql_1.2.3+dfsg.1-4+deb9u1_all.deb 1d92470ce50cb0e0dfe016922051bd32 70888 web extra roundcube-pgsql_1.2.3+dfsg.1-4+deb9u1_all.deb d1fda08d241f13fa849f9c4cbd63d127 661448 web extra roundcube-plugins_1.2.3+dfsg.1-4+deb9u1_all.deb 3171304c01bdc0c026fd1b44ee70a5a4 70864 web extra roundcube-sqlite3_1.2.3+dfsg.1-4+deb9u1_all.deb ada425403fffd24d62fc0545377893a1 1380 web extra roundcube_1.2.3+dfsg.1-4+deb9u1_all.deb 965254a44b0f1437450d52def29b94fe 9219 web extra roundcube_1.2.3+dfsg.1-4+deb9u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAloESYEACgkQ05pJnDwh pVKY8hAAqIL0uMcC6v5aTuW9KdmEZzM3SBO+IbNxbUFao/RMXfpe/+BUvB1RGVNe 93C9yL8Tb8qJ2FumjQ/+bEE62YG8JEQRlpD7NuhvYhf75NV0yQfIRkxSEoSjaqof W+11OVDkTGIk5YVgouHUp5jHOEJYPNr24yGGtnZM5FyAjqn7/R5g7L1M5CngYUXv dl2fBiSeH6wIUsEpE+94eo8yJNeSQCabPIMjg2lnWFs3+zzzgFboXBGc+n1Hv7yu sbDztqgaxV+9fb1IgK4Fo1cVVe0DtyZgpcUSfLZesUeJvuG6QV5qXmVy9Aj25SO9 geD3s3B+PBQtG8S03DugXjKg97S1HWDB9qpvy6WubSQOZ4HfRgEPuNBYyJMZ8i01 GvCJcOpMPM8VepEe01lBeFhb3eB92Gc2BbNA3fLoXs8KNiqttwy4+X5Lf5TzAGre GtZVkIBt/L9aeglGZSAYL/WP63IoLvz2lNQQixcYLdPGtSctn//0Q7DfNLrU4Uca IBUZ6Z47Ht3fs7FWTkmoVkYlnZYoMa9I0g9a7lHJNXxBecBt5yzBsl/GtUaSEyuj Fbmg+i6EsyE319aR4qc1KFhzavPo5fWYy8531FQkMz1LmlKtc+XoUBvJm2CPlNI+ zxFxxA9H56ggNRDt2nFf3N8sCLnxTfv/6mr9Ors5/f44S3md1gU= =P2ST -----END PGP SIGNATURE-----