[Bug 189933] [NEW] Please sync roundcube 0.1~rc2-6 (universe) from Debian unstable (main)

Michael Bienia michael at vorlon.ping.de
Thu Feb 7 14:54:01 GMT 2008


Public bug reported:

Binary package hint: roundcube

Please sync roundcube 0.1~rc2-6 (universe) from Debian unstable (main).
Changelog since current hardy version 0.1~rc2-4:

roundcube (0.1~rc2-6) unstable; urgency=high

  [ Vincent Bernat ]
  * Bug fix: "CVE-2007-6321: Cross-site scripting (XSS) vulnerability",
    thanks to Micah Anderson (Closes: #455840). The patch is from
    http://lists.roundcube.net/mail-archive/dev/2007-12/0000038.html and
    provided by Robin Elfrink. It has been modified with some functions
    stolen from Squirrelmail.
  * Finnish debconf template, thanks to Esko Arajärvi (Closes: #458244).

  [ Romain Beauxis ]
  * Added DM-Upload-Allowed: yes to control file.
  * Moved po-debconf to Build-Dep since it is needed for clean
    target. Thanks to lintian.

 -- Romain Beauxis <toots at rastageeks.org>  Sat, 26 Jan 2008 03:26:42
+0100

roundcube (0.1~rc2-5) unstable; urgency=low

  * Deal with old /etc/logrotate.d/roundcube by removing it if left
    untouched (Closes: #456546). Also deal with /etc/default/roundcube and
    /etc/cron.daily/roundcube.

 -- Vincent Bernat <bernat at luffy.cx>  Tue, 18 Dec 2007 23:02:46 +0100

** Affects: roundcube (Ubuntu)
     Importance: Wishlist
         Status: Confirmed

** Changed in: roundcube (Ubuntu)
   Importance: Undecided => Wishlist
       Status: New => Confirmed

-- 
Please sync roundcube 0.1~rc2-6 (universe) from Debian unstable (main)
https://bugs.launchpad.net/bugs/189933
You received this bug notification because you are a member of Ubuntu
Package Archive Administrators, which is a direct subscriber.



More information about the ubuntu-archive mailing list