Sync roundcube 0.3.1-3 (universe) from Debian testing (main)
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
roundcube (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Please sync roundcube 0.3.1-3 (universe) from Debian testing (main)
This is a bug fix only sync. It will also bring in a fix for
CVE-2010-0464
Changelog entries since current lucid version 0.3.1-2:
roundcube (0.3.1-3) unstable; urgency=high
* RFC 5321, section 4.5.3.1, asks to not impose any limits on length if
possible. We respect this by dropping limitation of the local-part of
an email address. Closes: #568360, #568537.
* Suggests php-auth-sasl to enable use of SASL mechanisms for mail
servers. Closes: #567550.
* Disable DNS prefetching to avoid information leakage through links
embedded in messages. This fixes CVE-2010-0464. Closes: #569660.
* Bump Standards-Version. No changes required.
-- Vincent Bernat <email address hidden> Sat, 13 Feb 2010 10:21:49 +0100
Changed in roundcube (Ubuntu): | |
status: | New → Fix Released |
2010-03-08 19:29:43 INFO roundcube_ 0.3.1.orig. tar.gz: already in distro - downloading from librarian 0.3.1.orig. tar.gz: cached> 0.3.1-3. dsc: downloading from http:// ftp.debian. org/debian/> 0.3.1-3. diff.gz: downloading from http:// ftp.debian. org/debian/> core_0. 3.1-2 [universe]. mysql_0. 3.1-2 [universe]. pgsql_0. 3.1-2 [universe]. sqlite_ 0.3.1-2 [universe].
2010-03-08 19:29:43 INFO - <roundcube_
2010-03-08 19:29:43 INFO - <roundcube_
[Updating] roundcube (0.3.1-2 [Ubuntu] < 0.3.1-3 [Debian])
* Trying to add roundcube...
2010-03-08 19:29:43 INFO - <roundcube_
I: roundcube [universe] -> roundcube-
I: roundcube [universe] -> roundcube_0.3.1-2 [universe].
I: roundcube [universe] -> roundcube-
I: roundcube [universe] -> roundcube-
I: roundcube [universe] -> roundcube-