[Pkg-roundcube-maintainers] Bug#857473: Bug#857473: roundcube: XSS issue in handling of a style tag inside of an svg element

Guilhem Moulin guilhem at guilhem.org
Tue Mar 14 03:16:18 UTC 2017


Control: tag -1 pending

Hi,

On Sat, 11 Mar 2017 at 20:29:11 +0100, Salvatore Bonaccorso wrote:
> 1.2.4 roundcube release fixed a XSS issue in handling of a style tag
> inside of an svg element.

Thanks for the ping and the pointers!  I applied the fix to 1.2.3
(unstable) and 1.1.5 (jessie-backports).

Could someone else in the team upload the two source packages?  I don't
have upload privileges :-P  (Also I didn't tag the releases.)

Cheers,
-- 
Guilhem.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-roundcube-maintainers/attachments/20170314/94b6fb24/attachment.sig>


More information about the Pkg-roundcube-maintainers mailing list