<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Arial,Helvetica,sans-serif;" dir="ltr">
<p></p>
<p><span>Hello,</span></p>
<p><span>regarding #1146838 and the Roundcube 1.6.19 security fixes:</span></p>
<p><span>The bug lists both</span></p>
<ul>
<li>
<p><span>bookworm: 1.6.5+dfsg-1+deb12u11</span></p>
</li><li>
<p><span>trixie: 1.6.18+dfsg-0+deb13u1</span></p>
</li></ul>
<p><span>as affected, while the fix in 1.6.19+dfsg-1 has so far reached unstable/testing.</span></p>
<p><span>Are updates planned for the supported stable releases as well?</span></p>
<p><span>In particular:</span></p>
<ul>
<li>
<p><span>Is a security/LTS update such as 1.6.5+dfsg-1+deb12u12 planned for bookworm?</span></p>
</li><li>
<p><span>Is an update for trixie planned, e.g. via trixie-security or a point update?</span></p>
</li><li>
<p><span>If so, is there already an approximate plan or package being prepared?</span></p>
</li></ul>
<p><span>I am asking because Roundcube is typically exposed as a public-facing web application, and the Debian security tracker still shows relevant issues as affecting the currently available bookworm/trixie packages.</span></p>
<p><span>Thank you for any information.</span></p>
<p><span>Best regards</span></p>
<p><span>Bjoern</span></p>
<br>
<p></p>
</div>
</body>
</html>