[prev in list] [next in list] [prev in thread] [next in thread] 

List:       roundcube-announce
Subject:    [Roundcube Announce] Security updates 0.9.5 and 0.8.7
From:       Thomas Bruederli <thomas () roundcube ! net>
Date:       2013-10-21 20:17:02
Message-ID: CAO3naw7Jquxm=jAmpn7x_RJ5xE-Vy13kLG858CUeUWe=yVk0qg () mail ! gmail ! com
[Download RAW message or body]

Dear Roundcube users

We just published new releases which fix a recently reported
vulnerability that allows an attacker to overwrite configuration
settings using user preferences. This can result in random file
access, manipulated SQL queries and even code execution. The latter
one only affects versions 0.8.6 and older.

Beside the security fix, the 0.9.5 release also includes other minor
bug fixes and improvements. Most notably it brings the default spell
checker back after Google suspended their public spell checking
service.

Please update your installations with the new versions or patch them
with the fixes listed below for the various older versions of
Roundcube.

Download the new versions from http://roundcube.net/download

Patch for 0.9.x:
https://github.com/roundcube/roundcubemail/commit/4109bb26ce.diff

Patch for 0.8.x:
https://github.com/roundcube/roundcubemail/commit/eb433aa33c.diff

Patch for 0.7.x:
https://github.com/roundcube/roundcubemail/commit/1972037274.diff

More information about the vulnerability will be published under CVE-2013-6172.

Kind regards,
Thomas
_______________________________________________
Roundcube Announcement mailing list
announce@lists.roundcube.net
http://lists.roundcube.net/mailman/listinfo/announce
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic