it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Moritz Muehlenhoff <jmm AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5743-1] roundcube security update
- Date: Thu, 8 Aug 2024 10:49:37 +0000
- List-archive: https://lists.debian.org/msgid-search/ZrSiwfqRE/teeBUd AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=qi/3AQxsU2ceY2aqgTr/hEEUDYgh7Djjt/MhhvhdKas=; b=WD bFxlImGcTrAHDe0IOQOqC/8AygsylFLm1Pct1sZd7ONZxK2mdWjst6bzd7aoOJeXuA3zViAr4WEDz 3glCcL7UNH+CLxtnEHbq7epLWlV77B/5hahCvor+YVXmXZUedKr+rDnb7Gwm4hKYJ+q+yDKqDiy2N lPRKnMWm1+5cY4p+f/jQyqeSMSC0PbUaGlvIjNd1gEFEvcNf/jReZeizRKmAMtDMD8QUTUdXZUtCb LVtAhhqhlADegzm5/Dd9TNMkweyO44qYwiCHn+5oHl5HJ4oTyuGTMVKPhdxuCoIj/RG5iuLKk08OU rXNHuM01FJWyGP3HQiX7ndH0oIiWhRag==;
- Old-return-path: <jmm AT seger.debian.org>
- Priority: urgent
- Resent-date: Thu, 8 Aug 2024 10:49:57 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <71QtZWesdIO.A.3vIB.VLKtmB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5743-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
August 08, 2024 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : roundcube
CVE ID : CVE-2024-42008 CVE-2024-42009 CVE-2024-42010
Multiple cross-site scripting vulnerabilities were discovered in
RoundCube webmail.
For the stable distribution (bookworm), these problems have been fixed in
version 1.6.5+dfsg-1+deb12u3.
We recommend that you upgrade your roundcube packages.
For the detailed security status of roundcube please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/roundcube
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAma0oZkACgkQEMKTtsN8
TjYxhA//UCLgEJvU4lRhVKupyDDsLgIxy4yWCvwDORqLtckWd83mJZXqbnUQYOUU
bvTaAHZ5XEEQ8mNwviDwgQZoSK7hY0ZHPb3NSbuc/2hl6aVUp9BqxzQ0iZ4haxiY
LtbqB29zpelXB0orRgH+rNISBLwAei2C+Vf213TKTmceiUGzhRxvkJKr4H++W2b6
7OkAoYqXIIH8OvKJmMgLirW/+toGR29c9F29d+C3Oyq/Qis0e/6osDIehFAdayro
EGJAvoUm72Vfe+syTF3csItT4vtf73qMb51CP67ATeGZ29j7bllqHgybLfjfZyI7
a4v5/VUGe+tDxvFiSsPCpBDuin843qt3rflrcy/LFaVvrYa7/SIcwV84uxVrjf85
mwwlIIud8n01EY7oPw0LK51a6MIrniFePAC3/KyYgBhya+hKE1T3JLQ/8XDRk/zo
M9Mqu1MbtamhjAeTdzkckRr+9ho+meY5un1MmnPtVIMoAaNhG/AteeqAuwCtucAF
Fg36kslrDwd+ojYUavIaE3AoRoLRzto5aAy46tXCE5JSakw2haKpBHoQfAhFwLZ/
59xds+gu7lRWp71Qhx2xBYclJ9XGNsdyx1g8Dzt0tPTQxwHCShP3fI2Wit8QOsWu
VeqdGxyqGT+cFrTmWRaVCKRQOsUgLjTpY2Nm5aKorBdD1HT8FU0=
=eXCy
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5743-1] roundcube security update, Moritz Muehlenhoff, 08.08.2024
Archiv bereitgestellt durch MHonArc 2.6.19+.