Bug#721592: roundcube: CVE-2013-5645

2013-09-03 Thread Salvatore Bonaccorso
Hi Vincent, On Tue, Sep 03, 2013 at 09:01:03AM +0200, Vincent Bernat wrote: > ❦ 3 septembre 2013 08:51 CEST, Salvatore Bonaccorso  : > > >> > Please adjust the affected versions in the BTS as needed. At least > >> > 0.9.2 looks affected. > >> > >> Hi Salvatore! > >> > >> Previous versions are

Bug#721592: roundcube: CVE-2013-5645

2013-09-03 Thread Vincent Bernat
❦ 3 septembre 2013 08:51 CEST, Salvatore Bonaccorso  : >> > Please adjust the affected versions in the BTS as needed. At least >> > 0.9.2 looks affected. >> >> Hi Salvatore! >> >> Previous versions are likely to be affected too. I will try to backport >> the patches. For version in Jessie and

Bug#721592: roundcube: CVE-2013-5645

2013-09-02 Thread Salvatore Bonaccorso
Hi Vincent! On Mon, Sep 02, 2013 at 08:42:14AM +0200, Vincent Bernat wrote: > ❦ 2 septembre 2013 08:31 CEST, Salvatore Bonaccorso  : > > > the following vulnerability was published for roundcube. > > > > CVE-2013-5645[0]: > > | Multiple cross-site scripting (XSS) vulnerabilities in Roundcube >

Bug#721592: roundcube: CVE-2013-5645

2013-09-01 Thread Vincent Bernat
❦ 2 septembre 2013 08:31 CEST, Salvatore Bonaccorso  : > the following vulnerability was published for roundcube. > > CVE-2013-5645[0]: > | Multiple cross-site scripting (XSS) vulnerabilities in Roundcube > | webmail before 0.9.3 allow user-assisted remote attackers to inject > | arbitrary web s

Bug#721592: roundcube: CVE-2013-5645

2013-09-01 Thread Salvatore Bonaccorso
Package: roundcube Severity: important Tags: security upstream patch fixed-upstream Hi, the following vulnerability was published for roundcube. CVE-2013-5645[0]: | Multiple cross-site scripting (XSS) vulnerabilities in Roundcube | webmail before 0.9.3 allow user-assisted remote attackers to inj