diff --git a/roundcubemail.changes b/roundcubemail.changes index cbd8562..561c8fe 100644 --- a/roundcubemail.changes +++ b/roundcubemail.changes @@ -4,6 +4,13 @@ Thu Aug 23 06:32:14 UTC 2012 - wr@rosenauer.org - Update to version 0.8.1 * lot of bugfixes and new features including new skin (please check the CHANGELOG) + * contains security related fixes (bnc#777446) + * Fix XSS vulnerability in message subject handling using + Larry skin (CVE-2012-3507) + * Fix XSS issue where plain signatures wasn't secured in HTML + mode (CVE-2012-3508) + * Fix XSS issue where href="javascript:" wasn't secured + (CVE-2012-3508) ------------------------------------------------------------------- Sat May 12 17:59:17 UTC 2012 - wr@rosenauer.org