Vincent Bernat <ber...@debian.org> writes:

>  ❦ 22 juillet 2014 16:43 -0400, Andreas Kloeckner <andr...@tiker.net> :
>
>> Just wanted to let you know that roundcube is affected by
>>
>> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=755115
>>
>> because, in /usr/share/roundcube/program/lib/Roundcube/rcube_utils.php,
>> the new (and broken, in 5.6RC2) getallheaders() function is used if it
>> is available.
>>
>> The concrete functionality broken by this is the XHR to get the mail,
>> which causes the UI to show a "Server error" popup. This XHR checks for
>> an X-Roundcube-Request header with an auth token and can't find it
>> because of the extraneous NUL character in the string.
>
> I'll try to finish packaging 1.0.2 this week-end. Do you know if this
> problem also happens with this version?

I'd expect so:

https://github.com/roundcube/roundcubemail/blob/6b0106a32446a125fd8a4ea7b9637c2378d52f72/program/lib/Roundcube/rcube_utils.php#L718

Andreas

Attachment: pgpk0OMnwvPtl.pgp
Description: PGP signature

Reply via email to