Re: roundcube: CVE-2020-35730: XSS vulnerability via malious HTML or plaintext messages

2020-12-28 Thread Utkarsh Gupta
Hi Guilhem, On Mon, Dec 28, 2020 at 4:48 PM Guilhem Moulin wrote: > > Yes, please. I can take care of the DLA. Please feel free to upload to > > stretch-security. > > Thank you Utkarsh, uploaded! Awesome, thank you for your proactive work on this! \o/ I've rolled out the DLA announcement and

Re: roundcube: CVE-2020-35730: XSS vulnerability via malious HTML or plaintext messages

2020-12-28 Thread Guilhem Moulin
On Mon, 28 Dec 2020 at 12:10:46 +0530, Utkarsh Gupta wrote: > On Mon, Dec 28, 2020 at 8:28 AM Guilhem Moulin wrote: >> Debdiff tested and attached. I can upload if you'd like but would >> appreciate if you could take care of the DLA :-) > > Yes, please. I can take care of the DLA. Please feel

Re: roundcube: CVE-2020-35730: XSS vulnerability via malious HTML or plaintext messages

2020-12-27 Thread Utkarsh Gupta
Hi Guilhem, On Mon, Dec 28, 2020 at 8:28 AM Guilhem Moulin wrote: > Debdiff tested and attached. I can upload if you'd like but would > appreciate if you could take care of the DLA :-) Yes, please. I can take care of the DLA. Please feel free to upload to stretch-security. - u

roundcube: CVE-2020-35730: XSS vulnerability via malious HTML or plaintext messages

2020-12-27 Thread Guilhem Moulin
Dear LTS team, In a recent post roundcube webmail upstream has announced the following security fix for #978491: Cross-site scripting (XSS) via HTML or Plain text messages with malicious content (CVE-2020-35730) — responsible disclosure from Alex Birnberg Debdiff tested and