pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/mail



Module Name:    pkgsrc
Committed By:   taca
Date:           Thu Nov  9 16:28:55 UTC 2023

Modified Files:
        pkgsrc/mail/roundcube: Makefile.common distinfo
        pkgsrc/mail/roundcube-plugin-password: distinfo

Log Message:
mail/roundcube: update to 1.6.5

This is security release, quoted from release announce:

Security fix

Fix cross-site scripting (XSS) vulnerability in setting
Content-Type/Content-Disposition for attachment preview/download.
Credits for this finding go to Rene Rehme (rehme.infosec).

See the full changelogs in the release notes on the Github download pages
for the updated versions 1.6.5 and 1.5.6.

We strongly recommend to update all productive installations of Roundcube
1.6.x and 1.5.x with this new versions.

1.6.5 (2023-11-05)

* Fix PHP8 fatal error when parsing a malformed BODYSTRUCTURE (#9171)
* Fix duplicated Inbox folder on IMAP servers that do not use Inbox folder
  with all capital letters (#9166)
* Fix PHP warnings (#9174)
* Fix UI issue when dealing with an invalid managesieve_default_headers
  value (#9175)
* Fix bug where images attached to application/smil messages weren't
  displayed (#8870)
* Fix PHP string replacement error in utils/error.php (#9185)
* Fix regression where `smtp_user` did not allow pre/post strings
  before/after `%u` placeholder (#9162)
* Fix cross-site scripting (XSS) vulnerability in setting
  Content-Type/Content-Disposition for attachment preview/download


To generate a diff of this commit:
cvs rdiff -u -r1.32 -r1.33 pkgsrc/mail/roundcube/Makefile.common
cvs rdiff -u -r1.86 -r1.87 pkgsrc/mail/roundcube/distinfo
cvs rdiff -u -r1.34 -r1.35 pkgsrc/mail/roundcube-plugin-password/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/mail/roundcube/Makefile.common
diff -u pkgsrc/mail/roundcube/Makefile.common:1.32 pkgsrc/mail/roundcube/Makefile.common:1.33
--- pkgsrc/mail/roundcube/Makefile.common:1.32  Tue Oct 17 15:47:08 2023
+++ pkgsrc/mail/roundcube/Makefile.common       Thu Nov  9 16:28:55 2023
@@ -1,4 +1,4 @@
-# $NetBSD: Makefile.common,v 1.32 2023/10/17 15:47:08 taca Exp $
+# $NetBSD: Makefile.common,v 1.33 2023/11/09 16:28:55 taca Exp $
 #
 # used by mail/roundcube/Makefile
 # used by mail/roundcube/plugins.mk
@@ -10,7 +10,7 @@ GITHUB_PROJECT=       roundcubemail
 GITHUB_RELEASE=        ${RC_VERS}
 HOMEPAGE=      https://roundcube.net/
 
-RC_VERS=       1.6.4
+RC_VERS=       1.6.5
 
 USE_LANGUAGES=         # none
 USE_TOOLS+=            pax

Index: pkgsrc/mail/roundcube/distinfo
diff -u pkgsrc/mail/roundcube/distinfo:1.86 pkgsrc/mail/roundcube/distinfo:1.87
--- pkgsrc/mail/roundcube/distinfo:1.86 Tue Oct 17 15:47:08 2023
+++ pkgsrc/mail/roundcube/distinfo      Thu Nov  9 16:28:55 2023
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.86 2023/10/17 15:47:08 taca Exp $
+$NetBSD: distinfo,v 1.87 2023/11/09 16:28:55 taca Exp $
 
-BLAKE2s (roundcubemail-1.6.4-complete.tar.gz) = 02ec63308fe260213e31d30e1e38446ae1a6242db2a5be0c10564ced5a7555eb
-SHA512 (roundcubemail-1.6.4-complete.tar.gz) = ccfd6828ed0f9a25c3144133a9a0f091b7ef76251e74422fe90dc1eb6fdddee8522902869d97609cd594f0977ecb6eb7402378d390ae33d907d154a24a607f85
-Size (roundcubemail-1.6.4-complete.tar.gz) = 6027429 bytes
+BLAKE2s (roundcubemail-1.6.5-complete.tar.gz) = 9cee6e6a0167f50117b547d06e9b342c1906c151caf0c1bc52254a03289f127d
+SHA512 (roundcubemail-1.6.5-complete.tar.gz) = d5d108045dc0afcc1fda077cac82f3aef274702727d45395744a3228c2a0429199d411f1988fc3f8317040ce65735ba423e8a1a33bad77220d63821e8b29ae08
+Size (roundcubemail-1.6.5-complete.tar.gz) = 6028873 bytes
 SHA1 (patch-config_config.inc.php.sample) = 92a48a97b16fe3f5f4b9441fce762a559d8daca7
 SHA1 (patch-program_include_iniset.php) = 8a6c13c0c87d583ed60e43c01a4173d9d802a6a1
 SHA1 (patch-program_lib_Roundcube_rcube__mime.php) = bfefc6850d3db230dd4224491e895fe25a32e87a

Index: pkgsrc/mail/roundcube-plugin-password/distinfo
diff -u pkgsrc/mail/roundcube-plugin-password/distinfo:1.34 pkgsrc/mail/roundcube-plugin-password/distinfo:1.35
--- pkgsrc/mail/roundcube-plugin-password/distinfo:1.34 Tue Oct 17 15:47:09 2023
+++ pkgsrc/mail/roundcube-plugin-password/distinfo      Thu Nov  9 16:28:55 2023
@@ -1,6 +1,6 @@
-$NetBSD: distinfo,v 1.34 2023/10/17 15:47:09 taca Exp $
+$NetBSD: distinfo,v 1.35 2023/11/09 16:28:55 taca Exp $
 
-BLAKE2s (roundcubemail-1.6.4-complete.tar.gz) = 02ec63308fe260213e31d30e1e38446ae1a6242db2a5be0c10564ced5a7555eb
-SHA512 (roundcubemail-1.6.4-complete.tar.gz) = ccfd6828ed0f9a25c3144133a9a0f091b7ef76251e74422fe90dc1eb6fdddee8522902869d97609cd594f0977ecb6eb7402378d390ae33d907d154a24a607f85
-Size (roundcubemail-1.6.4-complete.tar.gz) = 6027429 bytes
+BLAKE2s (roundcubemail-1.6.5-complete.tar.gz) = 9cee6e6a0167f50117b547d06e9b342c1906c151caf0c1bc52254a03289f127d
+SHA512 (roundcubemail-1.6.5-complete.tar.gz) = d5d108045dc0afcc1fda077cac82f3aef274702727d45395744a3228c2a0429199d411f1988fc3f8317040ce65735ba423e8a1a33bad77220d63821e8b29ae08
+Size (roundcubemail-1.6.5-complete.tar.gz) = 6028873 bytes
 SHA1 (patch-plugins_password_helpers_passwd-expect) = 15e427a3c90bf7c0437a023b3f099abb5a139165



Home | Main Index | Thread Index | Old Index