--- - branch: MAIN date: Sat Dec 26 14:24:48 UTC 2015 files: - new: '1.78' old: '1.77' path: pkgsrc/mail/roundcube/Makefile pathrev: pkgsrc/mail/roundcube/Makefile@1.78 type: modified - new: '1.39' old: '1.38' path: pkgsrc/mail/roundcube/PLIST pathrev: pkgsrc/mail/roundcube/PLIST@1.39 type: modified - new: '1.48' old: '1.47' path: pkgsrc/mail/roundcube/distinfo pathrev: pkgsrc/mail/roundcube/distinfo@1.48 type: modified - new: '1.2' old: '1.1' path: pkgsrc/mail/roundcube/patches/patch-config.inc.php pathrev: pkgsrc/mail/roundcube/patches/patch-config.inc.php@1.2 type: modified - new: '1.2' old: '1.1' path: pkgsrc/mail/roundcube/patches/patch-rcube_mime_default pathrev: pkgsrc/mail/roundcube/patches/patch-rcube_mime_default@1.2 type: modified id: 20151226T142448Z.1e318a7f1d3c8c4d55f371e2801cea5f83031371 log: | Update roundcube to 1.1.4 including security fixes. * Fix a potential path traversal vulnerability. * Adds some measures against brute-force attacks RELEASE 1.1.4 ------------- - Add workaround for https://bugs.php.net/bug.php?id=70757 (#1490582) - Fix duplicate messages in list and wrong count after delete (#1490572) - Fix so Installer requires PHP5 - Make brute force attacks harder by re-generating security token on every failed login (#1490549) - Slow down brute-force attacks by waiting for a second after failed login (#1490549) - Fix .htaccess rewrite rules to not block .well-known URIs (#1490615) - Fix mail view scaling on iOS (#1490551) - Fix so database_attachments::cleanup() does not remove attachments from other sessions (#1490542) - Fix responses list update issue after response name change (#1490555) - Fix bug where message preview was unintentionally reset on check-recent action (#1490563) - Fix bug where HTML messages with invalid/excessive css styles couldn't be displayed (#1490539) - Fix redundant blank lines when using HTML and top posting (#1490576) - Fix redundant blank lines on start of text after html to text conversion (#1490577) - Fix HTML sanitizer to skip in output (#1490583) - Fix invalid LDAP query in ACL user autocompletion (#1490591) - Fix regression in displaying contents of message/rfc822 parts (#1490606) - Fix handling of message/rfc822 attachments on replies and forwards (#1490607) - Fix PDF support detection in Firefox > 19 (#1490610) - Fix path traversal vulnerability (CWE-22) in setting a skin (#1490620) - Fix so drag-n-drop of text (e.g. recipient addresses) on compose page actually works (#1490619) module: pkgsrc subject: 'CVS commit: pkgsrc/mail/roundcube' unixtime: '1451139888' user: taca