roundcubemail-0.9.5-1.fc20 security update
|Date Submitted:||2013-10-22 12:58:18|
|Date Released:||2013-10-22 18:29:52|
Roundcubemail just released new 0.9.5 version with fixes for VCE2013-6172(will be available soon).
We just published new releases which fix a recently reported vulnerability that allows an attacker to overwrite configuration settings using user preferences. This can result in random file access, manipulated SQL queries and even code execution. The latter one only affects versions 0.8.6 and older.
Beside the security fix, the 0.9.5 release also includes other minor bug fixes and improvements. Most notably it brings the default spell checker back after Google suspended their public spell checking service.Bugs Fixed1021735 - CVE-2013-6172: Vulnerability in handling _session argument of utils/save-prefs [fedora-all]bodhi - 2013-10-22 12:58:44This update has been submitted for testing by limb.
autoqa - 2013-10-22 13:17:36AutoQA: depcheck test PASSED on x86_64. Result log: http://autoqa.fedoraproject.org/report/14h6e (results are informative only)
autoqa - 2013-10-22 13:22:16AutoQA: depcheck test PASSED on i386. Result log: http://autoqa.fedoraproject.org/report/14h6z (results are informative only)
bodhi - 2013-10-22 17:10:20This update is currently being pushed to the Fedora 20 testing updates repository.
bodhi - 2013-10-22 18:53:54This update has been pushed to testing
bodhi - 2013-10-25 22:03:57This update has reached 3 days in testing and can be pushed to stable now if the maintainer wishes
pbrobinson (proventesters) - 2013-10-26 11:59:05works
bodhi - 2013-10-28 11:59:44This update has been submitted for stable by limb.
autoqa - 2013-10-28 13:08:08AutoQA: upgradepath test PASSED on noarch. Result log: http://autoqa.fedoraproject.org/report/15cb8 (results are informative only)
bodhi - 2013-11-10 05:20:59This update is currently being pushed to the Fedora 20 stable updates repository.
bodhi - 2013-11-10 05:31:59This update is currently being pushed to the Fedora 20 stable updates repository.
bodhi - 2013-11-10 07:15:08This update has been pushed to stable