-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 17 Jun 2024 04:10:38 +0200 Source: roundcube Binary: roundcube roundcube-core roundcube-mysql roundcube-pgsql roundcube-plugins roundcube-sqlite3 Architecture: all Version: 1.4.15+dfsg.1-1+deb11u3 Distribution: bullseye-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Guilhem Moulin Description: roundcube - skinnable AJAX based webmail solution for IMAP servers - metapack roundcube-core - skinnable AJAX based webmail solution for IMAP servers roundcube-mysql - metapackage providing MySQL dependencies for RoundCube roundcube-pgsql - metapackage providing PostgreSQL dependencies for RoundCube roundcube-plugins - skinnable AJAX based webmail solution for IMAP servers - plugins roundcube-sqlite3 - metapackage providing SQLite dependencies for RoundCube Closes: 1071474 Changes: roundcube (1.4.15+dfsg.1-1+deb11u3) bullseye-security; urgency=high . * Fix CVE-2024-37384: Cross-site scripting (XSS) vulnerability in handling list columns from user preferences. (Closes: #1071474) * Fix CVE-2024-37383: Cross-site scripting (XSS) vulnerability in handling SVG animate attributes. (Closes: #1071474) Checksums-Sha1: 56cc6c7204a6e10b1984500cc3589ba7ad05e5ac 4318548 roundcube-core_1.4.15+dfsg.1-1+deb11u3_all.deb d25cff76297e4c114fcffcd9bcc33d4a07561c74 94208 roundcube-mysql_1.4.15+dfsg.1-1+deb11u3_all.deb 9269104683e3d4ed2220517798588be904145752 94188 roundcube-pgsql_1.4.15+dfsg.1-1+deb11u3_all.deb 9175a260d17193be63e235ec2bf1d695dee4200d 928112 roundcube-plugins_1.4.15+dfsg.1-1+deb11u3_all.deb ef101ff0aefbc067f3044ca3f6858379f3e4575c 94164 roundcube-sqlite3_1.4.15+dfsg.1-1+deb11u3_all.deb a4aa3b36b7c54213747a74d2dcc1a26fedc80740 10571 roundcube_1.4.15+dfsg.1-1+deb11u3_all-buildd.buildinfo f703b53fe86a39fa8b416048225eb81a16b0ac3e 1452 roundcube_1.4.15+dfsg.1-1+deb11u3_all.deb Checksums-Sha256: 16231f9b9617a81706ef08114dedde26968d34cb0f60e563166611ec4a05d258 4318548 roundcube-core_1.4.15+dfsg.1-1+deb11u3_all.deb 90fa1c987aa708fd9d94057c3dc0152de397fa8714a887339efbf316c4ef14a5 94208 roundcube-mysql_1.4.15+dfsg.1-1+deb11u3_all.deb df9ca1f386f202d0c5c7414a527876c23da88958876f18508adfcd45c2c1cbea 94188 roundcube-pgsql_1.4.15+dfsg.1-1+deb11u3_all.deb a740c52e6f1a190d361e04fbd413d537646dd5ecdb81b538e24bb66b951e6f72 928112 roundcube-plugins_1.4.15+dfsg.1-1+deb11u3_all.deb f19db76ec2e57f2295ec49a6e14adeb73602cb6d499a51ee996c24cd026f49c6 94164 roundcube-sqlite3_1.4.15+dfsg.1-1+deb11u3_all.deb 62b74296d47dc3be55913cd644882414c583a9044888dbfcd18355e8c9da4d32 10571 roundcube_1.4.15+dfsg.1-1+deb11u3_all-buildd.buildinfo 8c0fe9977fdb5dc23509026e3ff5fa7746ef7a5f923a0d76015fe37e68fe7241 1452 roundcube_1.4.15+dfsg.1-1+deb11u3_all.deb Files: 0045f2aec13e2c3d66ccb8f97793a0a6 4318548 web optional roundcube-core_1.4.15+dfsg.1-1+deb11u3_all.deb 2867936f1f3c0ede3cdd0070388aa9ea 94208 web optional roundcube-mysql_1.4.15+dfsg.1-1+deb11u3_all.deb 70061dd65c01ac4172aacd98f036138c 94188 web optional roundcube-pgsql_1.4.15+dfsg.1-1+deb11u3_all.deb 341af9b560c6855b420a2644de40b066 928112 web optional roundcube-plugins_1.4.15+dfsg.1-1+deb11u3_all.deb f8e0a3fcb56c5debefd40a4d8bf68676 94164 web optional roundcube-sqlite3_1.4.15+dfsg.1-1+deb11u3_all.deb b440027674eeb8660aa0e8bebfb4a9f2 10571 web optional roundcube_1.4.15+dfsg.1-1+deb11u3_all-buildd.buildinfo 57b78512ada64fad46d2db68a8ce9598 1452 web optional roundcube_1.4.15+dfsg.1-1+deb11u3_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEQsM0t1ygJv2xcx3e4cagXJhOTXsFAmZxh9wACgkQ4cagXJhO TXvJNhAAnrk703i3x9Kgptj6cAnXm86YcGlMmIvIuH+Qyvpt0fchiQzS/sg6MTjb psALMzXKHVEOFRfM7cKAcrhQREKA/IIuhXr/+5OWLEi4JYkjG6EmYVG5xdsxOpK2 AiXqdsRgocYcdncYeP+WBa0TOjyBZnziK5XpifD8X+RU/Gdk14gXbbu8ETbiLXQT K1oG//ZeLBvNj7R32VCOFVe38skyHedo9X4BvaokcuBRTugT0ZN0pV07SiUvDNmE /R/brdnbzBhR2hz0WafibSEseYNIK521jK/RlgtnosJN4jBe+p/eM/ilhBfAVoO6 xHdzJc3UqkED5lZQ6NEZksU23NnjAHzhUT1utr9cPTr2etohRIDxR/jymG/P2V68 CoUWaLZHp/+FHDHwmxYCW9xlSC+pbB0MqTJPvDQB+IAlTqZd9G/usZU7d+TnHrpZ kO/v8qX8hUheoEKA66OgjT2BNAsvcP4TYWXi79B1neu79iww8vrRT4RWSPhhn5Q9 iyF/mqHTSZf99Y77AjIv90oU7YqHnDQv5ISvDLX7jxU9J7RInbcYzPa+IyhJzVG7 Pejw6mHONloaAWE3pjVRvM/RxTiRRl62mEa2fSljXDNxf1gPHk0K0PKJo6qar7wk piB9pF9EYLM2jtYEYuXugXUsc+vTGLr6F+32sedeFNdSwld7PBM= =aOv0 -----END PGP SIGNATURE-----