Bug#895184: [Pkg-roundcube-maintainers] Bug#895184: roundcube: CVE-2018-9846: check_request() bypass in archive plugin

2018-04-25 Thread Salvatore Bonaccorso
Hi Guilhem, On Wed, Apr 25, 2018 at 11:07:25PM +0200, Guilhem Moulin wrote: > On Sat, 21 Apr 2018 at 13:03:04 +0200, Guilhem Moulin wrote: > > On Sat, 21 Apr 2018 at 08:23:55 +0200, Salvatore Bonaccorso wrote: > >> Looks good to me, please do upload to security-master. > > > > Done. > > Shy

Bug#895184: [Pkg-roundcube-maintainers] Bug#895184: roundcube: CVE-2018-9846: check_request() bypass in archive plugin

2018-04-25 Thread Guilhem Moulin
On Sat, 21 Apr 2018 at 13:03:04 +0200, Guilhem Moulin wrote: > On Sat, 21 Apr 2018 at 08:23:55 +0200, Salvatore Bonaccorso wrote: >> Looks good to me, please do upload to security-master. > > Done. Shy ping, in case you missed the upload (embargoed on Sat 21 Apr at 10:50:21 UTC) :-) --

Bug#895184: [Pkg-roundcube-maintainers] Bug#895184: roundcube: CVE-2018-9846: check_request() bypass in archive plugin

2018-04-09 Thread Guilhem Moulin
On Mon, 09 Apr 2018 at 12:25:20 +0200, Guilhem Moulin wrote: > Thanks for the poke! Upstream fixed this earlier today: > > https://github.com/roundcube/roundcubemail/commit/e3dd5b66d236867572e68fcb80281e9268a0cfb0 My bad, it's only fixed in master and 1.3. Since 1.2 is still supported and

Bug#895184: [Pkg-roundcube-maintainers] Bug#895184: roundcube: CVE-2018-9846: check_request() bypass in archive plugin

2018-04-09 Thread Guilhem Moulin
Hi Salvatore, Thanks for the poke! Upstream fixed this earlier today: https://github.com/roundcube/roundcubemail/commit/e3dd5b66d236867572e68fcb80281e9268a0cfb0 > If you fix the vulnerability please also make sure to include the CVE > (Common Vulnerabilities & Exposures) id in your changelog