<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Arial,Helvetica,sans-serif;" dir="ltr">
<p><span>Hi Guilhem,</span></p>
<p><span>thanks for the clarification.</span></p>
<p><span><br>
</span></p>
<p><span>Just to make sure I understand the current situation correctly:</span></p>
<p><span>Does this mean that all Roundcube installations using the currently available Debian 12 and Debian 13 packages are currently vulnerable to at least some of the issues fixed in Roundcube 1.6.19?</span></p>
<p><span><span><br>
</span></span></p>
<p><span><span>And is my understanding correct that the updates for bookworm and trixie have effectively been held back while waiting for CVE IDs to be assigned?</span></span></p>
<p><span><span>I am asking because this would mean that known security issues remain unfixed in the supported Debian packages for the time being, even though upstream fixes are already available.</span></span></p>
<p><span><span><br>
</span></span></p>
<p><span><span>Is waiting for CVE assignment before publishing such updates normal Debian security practice in this situation, or is this an exceptional case?</span></span></p>
<p><span><br>
</span></p>
<p><span>Best regards</span><br>
<span>Björn</span></p>
<br>
<br>
<div style="color: rgb(0, 0, 0);">
<div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>Von:</b> Guilhem Moulin <guilhem@debian.org><br>
<b>Gesendet:</b> Dienstag, 29. September 2026 14:43<br>
<b>An:</b> Björn Wiggert (wiggert.it); 1146838@bugs.debian.org<br>
<b>Betreff:</b> Re: Bug#1146838: planned updates for bookworm and trixie?</font>
<div> </div>
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">Hi,<br>
<br>
On Tue, 29 Sep 2026 at 11:53:51 +0000, Björn Wiggert (wiggert.it) wrote:<br>
> Are updates planned for the supported stable releases as well?<br>
><br>
> In particular:<br>
><br>
>  *   Is a security/LTS update such as 1.6.5+dfsg-1+deb12u12 planned for bookworm?<br>
>  *   Is an update for trixie planned, e.g. via trixie-security or a point update?<br>
<br>
Yes.<br>
<br>
>  *   If so, is there already an approximate plan or package being prepared?<br>
<br>
I was waiting for the CVE IDs to be assigned, but given it didn't happen<br>
yet 3 weeks after the assignment request it might be worth issuing the<br>
updates without CVE IDs.<br>
<br>
-- <br>
Guilhem.<br>
<br>
</div>
</span></font></div>
</div>
</body>
</html>