Fedora alert FEDORA-2015-1761 (roundcubemail)
From: | updates@fedoraproject.org | |
To: | package-announce@lists.fedoraproject.org | |
Subject: | [SECURITY] Fedora 20 Update: roundcubemail-1.0.5-1.fc20 | |
Date: | Sun, 15 Feb 2015 03:30:22 +0000 | |
Message-ID: | <20150215033022.04CA661370A4@bastion01.phx2.fedoraproject.org> |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-1761 2015-02-06 00:20:03 -------------------------------------------------------------------------------- Name : roundcubemail Product : Fedora 20 Version : 1.0.5 Release : 1.fc20 URL : http://www.roundcube.net Summary : Round Cube Webmail is a browser-based multilingual IMAP client Description : RoundCube Webmail is a browser-based multilingual IMAP client with an application-like user interface. It provides full functionality you expect from an e-mail client, including MIME support, address book, folder manipulation, message searching and spell checking. RoundCube Webmail is written in PHP and requires a database: MySQL, PostgreSQL and SQLite are known to work. The user interface is fully skinnable using XHTML and CSS 2. -------------------------------------------------------------------------------- Update Information: Cross-site scripting vulnerability has been fixed in Roundcube 1.0.5 version. http://roundcube.net/news/2015/01/24/security-update-1.0.5/ http://trac.roundcube.net/wiki/Changelog#RELEASE1.0.5 http://trac.roundcube.net/ticket/1490227 CVE request: http://www.openwall.com/lists/oss-security/2015/01/31/3 -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 5 2015 Jon Ciesla <limburgher@gmail.com> - 1.0.5-1 - Fix for security issues. * Sat Dec 20 2014 Adam Williamson <awilliam@redhat.com> - 1.0.4-2 - drop tinymce bbcode plugin for safety (CVE-2012-4230) * Sat Dec 20 2014 Adam Williamson <awilliam@redhat.com> - 1.0.4-1 - new release 1.0.4 (security update) * Tue Oct 14 2014 Adam Williamson <awilliam@redhat.com> - 1.0.3-1 - update to 1.0.3 - drop small chunk of confpath.patch that got done upstream * Mon Jul 21 2014 Adam Williamson <awilliam@redhat.com> - 1.0.2-1 - Update to 1.0.2 * Sun Jun 8 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Mon Jun 2 2014 Robert Scheck <robert@fedoraproject.org> - 1.0.1-1 - Update to 1.0.1 * Thu May 8 2014 Remi Collet <remi@fedoraproject.org> - 1.0.0-2 - Update to 1.0.0 - provide the installer - cleanup some config options from previous version - requires mailcap for /etc/mime.types - explicitly requires all needed extensions -------------------------------------------------------------------------------- References: [ 1 ] Bug #1188203 - CVE-2015-1433 roundcubemail: crooss-site scripting in style attribute handling [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1188203 [ 2 ] Bug #1188202 - CVE-2015-1433 roundcubemail: crooss-site scripting in style attribute handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1188202 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update roundcubemail' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...