UbuntuUpdates.org

Package "roundcube-plugins"

Name: roundcube-plugins

Description:

skinnable AJAX based webmail solution for IMAP servers - plugins

Latest version: 1.6.2+dfsg-1ubuntu0.1
Release: mantic (23.10)
Level: updates
Repository: universe
Head package: roundcube
Homepage: https://www.roundcube.net/

Links


Download "roundcube-plugins"


Other versions of "roundcube-plugins" in Mantic

Repository Area Version
base universe 1.6.2+dfsg-1
security universe 1.6.2+dfsg-1ubuntu0.1

Changelog

Version: 1.6.2+dfsg-1ubuntu0.1 2024-02-26 07:06:51 UTC

  roundcube (1.6.2+dfsg-1ubuntu0.1) mantic-security; urgency=medium

  * SECURITY UPDATE: cross-site scripting vulnerability
    - debian/patches/CVE-2023-43770.patch: Fix cross-site scripting (XSS)
      vulnerability in handling of linkrefs in plain text messages
    - CVE-2023-43770

 -- Nishit Majithia <email address hidden> Fri, 23 Feb 2024 10:31:46 +0530

CVE-2023-43770 Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/l



About   -   Send Feedback to @ubuntu_updates