<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Arial,Helvetica,sans-serif;" dir="ltr">
<p></p>
<p data-pm-slice="1 1 []"><span>Hi Guilhem,</span></p>
<p><span>thanks, that makes sense.</span></p>
<p><span><br>
</span></p>
<p><span>Given that the affected Debian 12 and Debian 13 packages are currently exposed to known issues, would there be any chance to get the fix published out of the normal CVE timing, i.e. before CVE IDs are assigned?</span></p>
<p><span><br>
</span></p>
<p><span>Even a targeted security update with the already available upstream fixes would help reduce the exposure for production Roundcube installations.</span></p>
<p><span><br>
</span></p>
<p><span>Björn</span></p>
<br>
<p></p>
<br>
<br>
<div style="color: rgb(0, 0, 0);">
<div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>Von:</b> Guilhem Moulin <guilhem@debian.org><br>
<b>Gesendet:</b> Dienstag, 29. September 2026 16:06<br>
<b>An:</b> Björn Wiggert (wiggert.it)<br>
<b>Cc:</b> 1146838@bugs.debian.org<br>
<b>Betreff:</b> Re: Bug#1146838: planned updates for bookworm and trixie?</font>
<div> </div>
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">On Tue, 29 Sep 2026 at 13:24:48 +0000, Björn Wiggert (wiggert.it) wrote:<br>
> Does this mean that all Roundcube installations using the currently<br>
> available Debian 12 and Debian 13 packages are currently vulnerable to<br>
> at least some of the issues fixed in Roundcube 1.6.19?<br>
<br>
Yes.<br>
<br>
> And is my understanding correct that the updates for bookworm and<br>
> trixie have effectively been held back while waiting for CVE IDs to be<br>
> assigned?<br>
<br>
Yes.<br>
<br>
> I am asking because this would mean that known security issues remain<br>
> unfixed in the supported Debian packages for the time being, even<br>
> though upstream fixes are already available.<br>
><br>
> Is waiting for CVE assignment before publishing such updates normal<br>
> Debian security practice in this situation, or is this an exceptional<br>
> case?<br>
<br>
Ideally each upstream project would have an embargoed process with its<br>
downstreams and request CVE IDs themselves (in coordinations with the<br>
reporters). This is not the case here.<br>
<a href="https://github.com/roundcube/roundcubemail/issues/10123" id="LPlnk535618">https://github.com/roundcube/roundcubemail/issues/10123</a><br>
<br>
-- <br>
Guilhem.<br>
<br>
</div>
</span></font></div>
</div>
</body>
</html>