Hello all, I have prepared an update for roundcube (0.7.2-9+deb7u9) to address CVE-2017-16651. The patch from upstream required significant changes in order to adapt it to the older roundcube in wheezy. I have tested the patch and, based on guidance from upstream, paid special attention to the ability to send messages with attachments. Everything appears to be in order based on my testing. However, I would feel more comfortable if before I upload someone who has an actual roundcube deployment could test the packages:
https://people.debian.org/~roberto/ As soon as I receive confirmation (or some days pass without any negative feedback), then I will upload the packages. Regards, -Roberto -- Roberto C. Sánchez