[Pkg-roundcube-maintainers] Bug#1146838: planned updates for bookworm and trixie?
Guilhem Moulin
guilhem at debian.org
Tue Sep 29 15:06:42 BST 2026
On Tue, 29 Sep 2026 at 13:24:48 +0000, Björn Wiggert (wiggert.it) wrote:
> Does this mean that all Roundcube installations using the currently
> available Debian 12 and Debian 13 packages are currently vulnerable to
> at least some of the issues fixed in Roundcube 1.6.19?
Yes.
> And is my understanding correct that the updates for bookworm and
> trixie have effectively been held back while waiting for CVE IDs to be
> assigned?
Yes.
> I am asking because this would mean that known security issues remain
> unfixed in the supported Debian packages for the time being, even
> though upstream fixes are already available.
>
> Is waiting for CVE assignment before publishing such updates normal
> Debian security practice in this situation, or is this an exceptional
> case?
Ideally each upstream project would have an embargoed process with its
downstreams and request CVE IDs themselves (in coordinations with the
reporters). This is not the case here.
https://github.com/roundcube/roundcubemail/issues/10123
--
Guilhem.
More information about the Pkg-roundcube-maintainers
mailing list