[Pkg-roundcube-maintainers] Bug#1052059: roundcube: Please apply security fix from 1.6.3

Guilhem Moulin guilhem at debian.org
Fri Sep 22 08:56:59 BST 2023


Control: retitle -1 roundcube: CVE-2023-43770: XSS vulnerability in handling of linkrefs in plain text messages

On Mon, 18 Sep 2023 at 13:59:47 +0200, Guilhem Moulin wrote:
> I requested a CVE ID for this issue.

CVE-2023-43770 for this.  I'll suggest debdiffs targetting {bullseye,bookworm}-
security after the week-end.

-- 
Guilhem.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-roundcube-maintainers/attachments/20230922/e457f5f6/attachment.sig>


More information about the Pkg-roundcube-maintainers mailing list