Version 1.1.11
This is a security update to the stable version 1.1. It fixes a recently reported vulnerability allowing IMAP command injection via a GET parameters. More details about this are published under CVE-2018-9846.
The second fix is about a missed remote content blocking on HTML messages with specially crafted image and style tags.
We strongly recommend to update all productive installations of Roundcube 1.1.x. Please do backup your data before updating!
CHANGELOG
Please login to add feedback.
This update has been submitted for testing by remi.
This update has been pushed to testing.
Please update to v1.1.12 instead, which was released yesterday and fixes a regression
This update has been obsoleted by roundcubemail-1.1.12-1.el7.