-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 17 Jun 2024 03:15:26 +0200 Source: roundcube Binary: roundcube roundcube-core roundcube-mysql roundcube-pgsql roundcube-plugins roundcube-sqlite3 Architecture: all Version: 1.6.5+dfsg-1+deb12u2 Distribution: bookworm-security Urgency: high Maintainer: all Build Daemon (x86-csail-02) Changed-By: Guilhem Moulin Description: roundcube - skinnable AJAX based webmail solution for IMAP servers - metapack roundcube-core - skinnable AJAX based webmail solution for IMAP servers roundcube-mysql - metapackage providing MySQL dependencies for RoundCube roundcube-pgsql - metapackage providing PostgreSQL dependencies for RoundCube roundcube-plugins - skinnable AJAX based webmail solution for IMAP servers - plugins roundcube-sqlite3 - metapackage providing SQLite dependencies for RoundCube Closes: 1071474 Changes: roundcube (1.6.5+dfsg-1+deb12u2) bookworm-security; urgency=high . * Fix CVE-2024-37384: Cross-site scripting (XSS) vulnerability in handling list columns from user preferences. (Closes: #1071474) * Fix CVE-2024-37383: Cross-site scripting (XSS) vulnerability in handling SVG animate attributes. (Closes: #1071474) Checksums-Sha1: d6d4d6f84e88d2589429d759e4a5dfac6c094d67 4697108 roundcube-core_1.6.5+dfsg-1+deb12u2_all.deb a97c380b2816498710fb170beb6603580b1dd165 94968 roundcube-mysql_1.6.5+dfsg-1+deb12u2_all.deb 7488b020aedc0e1cb0109ef692494a17668d0290 94952 roundcube-pgsql_1.6.5+dfsg-1+deb12u2_all.deb 1e1383e2535d35632816f4c704f627dcb33bdab3 776668 roundcube-plugins_1.6.5+dfsg-1+deb12u2_all.deb e3f7160c7ff9375505cb3285bfa3f0f6e4f9e977 94928 roundcube-sqlite3_1.6.5+dfsg-1+deb12u2_all.deb bdac28b6b6842e58254ccd1caa2d309ee5598472 13777 roundcube_1.6.5+dfsg-1+deb12u2_all-buildd.buildinfo 1d4af8162bd9caca413b3660a85e97e5015982ba 1296 roundcube_1.6.5+dfsg-1+deb12u2_all.deb Checksums-Sha256: 271d347687581077c279656f5d8586d2eef096d7094fe035ec4ce926a8ed5c91 4697108 roundcube-core_1.6.5+dfsg-1+deb12u2_all.deb 18510dc510063f13f2ffcae81fcc8c923fd27652d5e34d38a88840df9ee3a027 94968 roundcube-mysql_1.6.5+dfsg-1+deb12u2_all.deb 009cb000655c171727252cfa063a6d0ced62e0401c2e91c6471ee671d17caad8 94952 roundcube-pgsql_1.6.5+dfsg-1+deb12u2_all.deb 82847efc9030b71c5d3590058eb34af0435fe361100b0cb3229873339a46aa13 776668 roundcube-plugins_1.6.5+dfsg-1+deb12u2_all.deb 6577b99402bce853538a6834a0a54b357a2192cc15e1d41d04f6e410ae64a273 94928 roundcube-sqlite3_1.6.5+dfsg-1+deb12u2_all.deb 5a12547a3594d0eba6eb2842c14115064ee5f5efb52c02002f2a4ed23edc373d 13777 roundcube_1.6.5+dfsg-1+deb12u2_all-buildd.buildinfo 74b5e16db05c25bac0787ae4a088a428aa6a268537f4ffb405c48fcea8b6030a 1296 roundcube_1.6.5+dfsg-1+deb12u2_all.deb Files: 97bf46ae1e9336070d876fa8b81e3718 4697108 web optional roundcube-core_1.6.5+dfsg-1+deb12u2_all.deb 76e763bd723e00cd2803cbc63ce2ce21 94968 web optional roundcube-mysql_1.6.5+dfsg-1+deb12u2_all.deb acf39f851e1301217947237f19b156cd 94952 web optional roundcube-pgsql_1.6.5+dfsg-1+deb12u2_all.deb b652e122ae1e2500ff4fdca9b06b9d4f 776668 web optional roundcube-plugins_1.6.5+dfsg-1+deb12u2_all.deb acc113d34916ace15cfe35d57e651027 94928 web optional roundcube-sqlite3_1.6.5+dfsg-1+deb12u2_all.deb d4774ab8d56b067f0a1ee747b7a66365 13777 web optional roundcube_1.6.5+dfsg-1+deb12u2_all-buildd.buildinfo 9867863a2c31191afda4bfe069a3c044 1296 web optional roundcube_1.6.5+dfsg-1+deb12u2_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEzcbx6nIE/ydHa1FFigL77i1GSVkFAmZxh+8ACgkQigL77i1G SVlEQw/+MB6nn1G389GZG/V7JjGr14m9eZNUWVlzTzi71s6GCDgVtB8AX6NA2zET o9c9FKwOfBN0Kd0zaNe5A+lBxFQ9QM8z2K8PQWUf84Q6Buylkev+4GUjjnDrbyMg Wq9tc9RQWQBYqmvrzNruTD+CPOddDXUcCdFk7LU01pFkXSud8E1fTMiqBuBOmBKY E2snm9zkZm/mHIfDtCCgY0YRerlnhlRkWJ2GsZpb2XWRBsvuF8zSm0pggKoX+IYK O0RljDqpVC5LLVz1u3rNZX23jP0YeXZ7+M4Hy4XWxVejeuShzMDC6ONn3kx7QTnv SZOrb8YflBfWSHy2PsOt5KAaB40bxmn8UD2tvH88r1zrCB2wmiVMvLl7qFCHN032 VVLYnqyHa8qtcOOf1ECLg/DZ+exUfXQuD8L8KEPhLZ31QhW8F20VuWh2W8z9M3/F N06nCDXDZJP6y8lb12SpBaB5c5EW0/pbX5na9wCH7D+xFeySdfTIWJoccTFci1Ih vK5bQIQWjwo9BlH80MAEZMbaMugBhcskGk/Q3lRvTfK1VILC4lG5frsaTvrF3B/U R5eanIBzG8gXn7SGCT8gNPbcVeEBWrcQNGZSCzRAPI56fHefe7SleLYjxvZfatWd xLyn/bm/78SxpIwF2CP71j+tVHK1GNo3ZzAoQMyEFhBxJvwHfqE= =7e9E -----END PGP SIGNATURE-----