[Roundcube Announce] Updates 1.1.2 and 1.0.6 released

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view

[Roundcube Announce] Updates 1.1.2 and 1.0.6 released

Thomas Bruederli-2
Dear Roundcube users

We just published updates to both stable versions 1.0 and 1.1 after
fixing many minor bugs and adding some security improvements to the
1.1 release branch. Version 1.0.6 comes with cherry-picked fixes from
the more recent version to ensure proper long term support especially
in regards of security and compatibility.

The security-related fixes in particular are:

 - XSS vulnerability in _mbox argument
 - security improvement in contact photo handling
 - potential info disclosure from temp directory

See the full changelog here: http://trac.roundcube.net/wiki/Changelog

Both versions are considered stable and we recommend to update all
productive installations of Roundcube with either of these versions.
Download them from https://roundcube.net/download

As usual, don't forget to backup your data before updating.

And there's one more thing:

Our crowdfunding campaign for Roundcube Next is still ongoing and has
just been updated with more details of what we want to achieve. We'd
much appreciate your support for this exciting new project. Please
visit https://roundcu.be/next and spread the word about it.
Roundcube Announcement mailing list
[hidden email]