Processed: Re: Bug#1052611: bullseye-pu: package roundcube/1.4.14+dfsg.1-1~deb11u1

2023-09-26 Thread Debian Bug Tracking System
Processing control commands: > tags -1 confirmed Bug #1052611 [release.debian.org] bullseye-pu: package roundcube/1.4.14+dfsg.1-1~deb11u1 Added tag(s) confirmed. -- 1052611: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1052611 Debian Bug Tracking System Contact ow...@bugs.debian.org with p

Bug#1052611: bullseye-pu: package roundcube/1.4.14+dfsg.1-1~deb11u1

2023-09-26 Thread Adam D. Barratt
Control: tags -1 confirmed On Mon, 2023-09-25 at 12:11 +0200, Guilhem Moulin wrote: > roundcube 1.4.13+dfsg.1-1~deb11u1 is vulnerable to CVE-2023-43770: > cross-site scripting (XSS) vulnerability in handling of linkrefs in > plain text messages. > Please go ahead. Regards, Adam

Bug#1052611: bullseye-pu: package roundcube/1.4.14+dfsg.1-1~deb11u1

2023-09-25 Thread Guilhem Moulin
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: roundc...@packages.debian.org Control: affects -1 + src:roundcube [ Reason ] roundcube 1.4.13+dfsg.1-1~deb11u1 is vulnerable to CVE-2023-43770: cross-site scripting