-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 29 Apr 2020 22:10:57 +0200 Source: roundcube Architecture: source Version: 1.4.4+dfsg.1-1 Distribution: unstable Urgency: high Maintainer: Debian Roundcube Maintainers <pkg-roundcube-maintain...@alioth-lists.debian.net> Changed-By: Guilhem Moulin <guil...@debian.org> Closes: 958642 959140 959142 Changes: roundcube (1.4.4+dfsg.1-1) unstable; urgency=high . * New upstream release, including security fixes for: - Cross-Site Scripting (XSS) vulnerability via malicious HTML messages (Closes: #959140) - CSRF attack can cause an authenticated user to be logged out (Closes: #959142) * Include krb_authentication plugin to the roundcube-plugins binary package. Upstream ships this (core) plugin since 1.2-beta but somehow it never made it to the Debian package. Thanks to Mike Gabriel for the poke. (Closes: #958642) * d/control: Update Maintainer: field to use @alioth-lists.debian.net not deprecated @lists.alioth.debian.org. Checksums-Sha1: 41f0c0e550b6d70a9cdf843f7889f480525700cb 2466 roundcube_1.4.4+dfsg.1-1.dsc 2f4d39b92b4a7d60d7fb809fd46c54a698a28a01 2972040 roundcube_1.4.4+dfsg.1.orig.tar.xz dfd9ec14cebb333f5dddbbff732ef2aecf6de95d 1227304 roundcube_1.4.4+dfsg.1-1.debian.tar.xz d1b566fb85723d3c0dd91b9c993b857fe4bb55a5 9490 roundcube_1.4.4+dfsg.1-1_amd64.buildinfo Checksums-Sha256: 7f1712368a8e9b44e701f82a9b8984e5e28c7c61d6ef3d5014ef7df4fbc07b5c 2466 roundcube_1.4.4+dfsg.1-1.dsc 9f627d1d1fb0aca083a4a0aed8548175c8992c23336355ae85f875ce11a388a2 2972040 roundcube_1.4.4+dfsg.1.orig.tar.xz 7895bf5f5ede7f074da9cb413f4fa40469862a1bcf28dc39ebf44835264b137f 1227304 roundcube_1.4.4+dfsg.1-1.debian.tar.xz 42d4b41533b32cba1c7236df6807c02f939fc45518c56ab12a482e8240f82ea2 9490 roundcube_1.4.4+dfsg.1-1_amd64.buildinfo Files: 94549497be5bfeb5b48792b05eaf7114 2466 web optional roundcube_1.4.4+dfsg.1-1.dsc abb497395232c3b67e39aa91311a8a74 2972040 web optional roundcube_1.4.4+dfsg.1.orig.tar.xz be8166b8eb80cb7a880fee586f82e577 1227304 web optional roundcube_1.4.4+dfsg.1-1.debian.tar.xz 3ecacc03ec1cfa5c1164853238ed9b3f 9490 web optional roundcube_1.4.4+dfsg.1-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAl6p5kgACgkQ05pJnDwh pVIGrBAAkbjWCmw/41EMtMH1CVpQIKlO8meeGHPqTt21XYPzjsIu8/3VRNbajeFV fMqHLgdCEXx9yinsBpeAx3PSfqT0hzZo37duuDZpAufVAtLIJcSy+1ROk3rciZVd wce7SQTSrPaIVUPKC1qTiTouM4oeAksaLVUrP0YMpO/84ol/atvke6HD7aiFG4R4 d1EGdby4DyvnpsQ4ePxFPX3sb1CJetaX0fEdeqpcILfxosbX/HrZ3RTKi92pimjm p5OpzWx95NxfNhiVJGYa28CyGw8eTub4aiOXkFnRyCa6tEvRarhrgSsk7zW9EeWi FR6ww7KfRURobvoYxI1lQbPxe/xEZaYvFQ3oFLifDPMwJ0FR9BgpnuN0wPkEijwA GFFypFjqOn/cCluJA4p/kumdm/7FdUV2p+SLs7abw4kN/sFm7GSHMJiJHkIwZZXt kImI4b/LL0YTJuy0Zarg2FZRnnpGBJkI4mAawcqcfO77hDH8TfjPJV/YIm1F8aHS If8D5CsiR6oTN3sP10wWtdC1rgzu1ssfQjlUTB9qUm1YnihyPAt8q2QPmW1Z71tL rBgxfCZVP/mS86k2ZcdQVVJDMUuDJKlIwFpJ4se1UAnAHe0Wg74C5AuZ3vQZqkzw 50nMVcCE+JD3HR/bXCQ7grCtrG0dTCG+tszvwHYbDBWDeZ9Wamk= =76hR -----END PGP SIGNATURE-----