stable

roundcubemail-1.6.12-1.fc43

FEDORA-2025-58eb59741f created by remi 9 months ago for Fedora 43

Release 1.6.12

  • Support IPv6 in database DSN (#9937)
  • Don't force specific error_reporting setting
  • Fix compatibility with PHP 8.5 regarding array_first()
  • Remove X-XSS-Protection example from .htaccess file (#9875)
  • Fix "Assign to group" action state after creation of a first group (#9889)
  • Fix bug where contacts search would fail if contactlist_fields contained vcard fields (#9850)
  • Fix bug where an mbox export file could include inconsistent message delimiters (#9879)
  • Fix parsing of inline styles that aren't well-formatted (#9948)
  • Fix Cross-Site-Scripting vulnerability via SVG's animate tag
  • Fix Information Disclosure vulnerability in the HTML style sanitizer

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2025-58eb59741f

This update has been submitted for testing by remi.

9 months ago

This update's test gating status has been changed to 'ignored'.

9 months ago
User Icon amessina provided feedback 9 months ago
karma

This update has been pushed to testing.

9 months ago

This update can be pushed to stable now if the maintainer wishes

9 months ago

remi edited this update.

9 months ago

remi edited this update.

9 months ago
User Icon pbrobinson commented & provided feedback 9 months ago
karma

LGTM

BZ#2423517 CVE-2025-68461 roundcubemail: Roundcube Webmail: Cross-Site Scripting (XSS) vulnerability via crafted SVG animate tag [fedora-43]
BZ#2423531 CVE-2025-68460 roundcubemail: Roundcube Webmail: Information Disclosure via HTML Style Sanitizer [fedora-43]

This update has been submitted for stable by bodhi.

9 months ago

This update has been pushed to stable.

9 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
2
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
9 months ago
in testing
9 months ago
in stable
9 months ago
modified
9 months ago
approved
9 months ago
BZ#2423517 CVE-2025-68461 roundcubemail: Roundcube Webmail: Cross-Site Scripting (XSS) vulnerability via crafted SVG animate tag [fedora-43]
0
1
BZ#2423531 CVE-2025-68460 roundcubemail: Roundcube Webmail: Information Disclosure via HTML Style Sanitizer [fedora-43]
0
1

Automated Test Results