On Wed, Jun 03, 2020 at 01:51:40PM +0200, Guilhem Moulin wrote: > Hi, > > On Wed, 03 Jun 2020 at 12:34:09 +0100, David Pottage wrote: > > Roundcube have just announced a new release which includes security > > fixes. > > > > What is the timeline to updated the Debian package in backports? > > I'm preparing an upload to unstable, from there it should take 2 more > days (like for 1.4.4).
Thanks for working on roundcube in Debian! Do you know what the story is with these vulnerabilities and stable/oldstable? I note that there is no 1.2.x release in this advisory even though there was just over a month ago (and there it was described as being LTS). I couldn't find anything about whether the vulnerabilities apply to 1.2 or any change to the 1.2.x support status. Cheers Dominic