FEDORA-2020-2a1a6a8432 created by remi 6 months ago for Fedora 31
stable

RELEASE 1.4.6

  • Installer: Fix regression in SMTP test section (#7417)

RELEASE 1.4.5

  • Fix bug in extracting required plugins from composer.json that led to spurious error in log (#7364)
  • Fix so the database setup description is compatible with MySQL 8 (#7340)
  • Markasjunk: Fix regression in jsevent driver (#7361)
  • Fix missing flag indication on collapsed thread in Larry and Elastic (#7366)
  • Fix default keyservers (use keys.openpgp.org), add note about CORS (#7373, #7367)
  • Password: Fix issue with Modoboa driver (#7372)
  • Mailvelope: Use sender's address to find pubkeys to check signatures (#7348)
  • Mailvelope: Fix Encrypt button hidden in Elastic (#7353)
  • Fix PHP warning: count(): Parameter must be an array or an object... in ID command handler (#7392)
  • Fix error when user-configured skin does not exist anymore (#7271)
  • Elastic: Fix aspect ratio of a contact photo in mail preview (#7339)
  • Fix bug where PDF attachments marked as inline could have not been attached on mail forward (#7382)
  • Security: Fix a couple of XSS issues in Installer (#7406)
  • Security: Fix XSS issue in template object 'username' (#7406)
  • Security: Better fix for CVE-2020-12641
  • Security: Fix cross-site scripting (XSS) via malicious XML attachment

How to install

sudo dnf upgrade --advisory=FEDORA-2020-2a1a6a8432

This update has been submitted for testing by remi.

6 months ago

This update's test gating status has been changed to 'waiting'.

6 months ago

This update's test gating status has been changed to 'ignored'.

6 months ago

This update has obsoleted roundcubemail-1.4.5-1.fc31, and has inherited its bugs and notes.

6 months ago

This update's test gating status has been changed to 'greenwave_failed'.

6 months ago

This update's test gating status has been changed to 'ignored'.

6 months ago

This update has been pushed to testing.

6 months ago

remi edited this update.

6 months ago

remi edited this update.

6 months ago

This update can be pushed to stable now if the maintainer wishes

6 months ago

This update has been submitted for stable by bodhi.

6 months ago

This update has been pushed to stable.

6 months ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
6 months ago
in testing
6 months ago
in stable
6 months ago
modified
6 months ago
BZ#1848338 CVE-2020-13965 roundcubemail: XSS via a malicious XML attachment
0
0
BZ#1848339 CVE-2020-13965 roundcubemail: XSS via a malicious XML attachment [fedora-all]
0
0
BZ#1848341 CVE-2020-13964 roundcubemail: XSS via the username template object
0
0
BZ#1848342 CVE-2020-13964 roundcubemail: XSS via the username template object [fedora-all]
0
0

Automated Test Results