[Pkg-roundcube-maintainers] Bug#962124: roundcube: Cross-Site Scripting (XSS) vulnerability via malicious XML messages
Guilhem Moulin
guilhem at debian.org
Wed Jun 3 13:19:59 BST 2020
Source: roundcube
Severity: important
Tags: security
AFAICT no CVE was assigned for this yet. 1.2.x, 1.3.x and 1.4.x
branches are affected. Upstream fix:
1.4.x https://github.com/roundcube/roundcubemail/commit/ccaccae6653031b809b4347a60021951e19a0e43
1.3.x https://github.com/roundcube/roundcubemail/commit/884eb611627ef2bd5a2e20e02009ebb1eceecdc3
--
Guilhem.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-roundcube-maintainers/attachments/20200603/193ffe14/attachment.sig>
More information about the Pkg-roundcube-maintainers
mailing list