From 87af86c8fb72a7b0273d4753a6a85c2d8f4524a741c8aa2bcb089315bc0b1ffc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Aeneas=20Jai=C3=9Fle?= Date: Tue, 6 Aug 2024 15:49:48 +0000 Subject: [PATCH] OBS-URL: https://build.opensuse.org/package/show/server:php:applications/roundcubemail?expand=0&rev=175 --- roundcubemail.changes | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/roundcubemail.changes b/roundcubemail.changes index 6cccb9b..21d9e60 100644 --- a/roundcubemail.changes +++ b/roundcubemail.changes @@ -4,9 +4,9 @@ Tue Aug 6 15:14:35 UTC 2024 - Aeneas Jaißle - update to 1.6.8 This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities: - * Fix XSS vulnerability in post-processing of sanitized HTML content [CVE-2024-42009] + * Fix XSS vulnerability in post-processing of sanitized HTML content [CVE-2024-42009] [bsc#1228900] * Fix XSS vulnerability in serving of attachments other than HTML or SVG [CVE-2024-42008] - * Fix information leak (access to remote content) via insufficient CSS filtering [CVE-2024-42010] + * Fix information leak (access to remote content) via insufficient CSS filtering [CVE-2024-42010] [bsc#1228901] - For further changes, see https://github.com/roundcube/roundcubemail/releases/tag/1.6.8