Wed Jul 29 19:39:44 2020 UTC ()
Pullup ticket #6274 - requested by taca
mail/roundcube: security fix

Revisions pulled up:
- mail/roundcube-plugin-password/distinfo                       1.20
- mail/roundcube/Makefile.common                                1.20
- mail/roundcube/distinfo                                       1.71

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Tue Jul  7 04:37:26 UTC 2020

   Modified Files:
   	pkgsrc/mail/roundcube: Makefile.common distinfo
   	pkgsrc/mail/roundcube-plugin-password: distinfo

   Log Message:
   mail/roundcube: update to 1.4.7

   Update roundcube to 1.4.7.

   RELEASE 1.4.7
   -------------
   - Fix bug where subfolders of special folders could have been duplicated on folder list
   - Increase maximum size of contact jobtitle and department fields to 128 characters
   - Fix missing newline after the logged line when writing to stdout (#7418)
   - Elastic: Fix context menu (paste) on the recipient input (#7431)
   - Fix problem with forwarding inline images attached to messages with no HTML part (#7414)
   - Fix problem with handling attached images with same name when using database_attachments/redundant_attachments (#7455)
   - Security: Fix cross-site scripting (XSS) via HTML messages with malicious svg/namespace


(bsiegert)
diff -r1.19 -r1.19.2.1 pkgsrc/mail/roundcube/Makefile.common
diff -r1.70 -r1.70.2.1 pkgsrc/mail/roundcube/distinfo
diff -r1.19 -r1.19.2.1 pkgsrc/mail/roundcube-plugin-password/distinfo

cvs diff -r1.19 -r1.19.2.1 pkgsrc/mail/roundcube/Makefile.common (expand / switch to unified diff)

--- pkgsrc/mail/roundcube/Makefile.common 2020/06/09 00:25:19 1.19
+++ pkgsrc/mail/roundcube/Makefile.common 2020/07/29 19:39:44 1.19.2.1
@@ -1,26 +1,26 @@ @@ -1,26 +1,26 @@
1# $NetBSD: Makefile.common,v 1.19 2020/06/09 00:25:19 taca Exp $ 1# $NetBSD: Makefile.common,v 1.19.2.1 2020/07/29 19:39:44 bsiegert Exp $
2# 2#
3# used by mail/roundcube/Makefile 3# used by mail/roundcube/Makefile
4# used by mail/roundcube/plugins.mk 4# used by mail/roundcube/plugins.mk
5 5
6DISTNAME= roundcubemail-${RC_VERS}-complete 6DISTNAME= roundcubemail-${RC_VERS}-complete
7CATEGORIES= mail 7CATEGORIES= mail
8MASTER_SITES= ${MASTER_SITE_GITHUB:=roundcube/} 8MASTER_SITES= ${MASTER_SITE_GITHUB:=roundcube/}
9GITHUB_PROJECT= roundcubemail 9GITHUB_PROJECT= roundcubemail
10GITHUB_RELEASE= ${RC_VERS} 10GITHUB_RELEASE= ${RC_VERS}
11HOMEPAGE= https://roundcube.net/ 11HOMEPAGE= https://roundcube.net/
12 12
13RC_VERS= 1.4.6 13RC_VERS= 1.4.7
14 14
15USE_LANGUAGES= # none 15USE_LANGUAGES= # none
16USE_TOOLS+= pax 16USE_TOOLS+= pax
17EXTRACT_USING= bsdtar 17EXTRACT_USING= bsdtar
18NO_BUILD= yes 18NO_BUILD= yes
19WRKNAME= ${DISTNAME:S/-complete//} 19WRKNAME= ${DISTNAME:S/-complete//}
20WRKSRC= ${WRKDIR}/${WRKNAME} 20WRKSRC= ${WRKDIR}/${WRKNAME}
21 21
22DISTINFO_FILE?= ${PKGDIR}/../../mail/roundcube/distinfo 22DISTINFO_FILE?= ${PKGDIR}/../../mail/roundcube/distinfo
23 23
24PKG_SYSCONFSUBDIR?= roundcube 24PKG_SYSCONFSUBDIR?= roundcube
25 25
26PKG_GROUPS_VARS+= WWW_GROUP 26PKG_GROUPS_VARS+= WWW_GROUP

cvs diff -r1.70 -r1.70.2.1 pkgsrc/mail/roundcube/distinfo (expand / switch to unified diff)

--- pkgsrc/mail/roundcube/distinfo 2020/06/09 00:25:19 1.70
+++ pkgsrc/mail/roundcube/distinfo 2020/07/29 19:39:44 1.70.2.1
@@ -1,9 +1,9 @@ @@ -1,9 +1,9 @@
1$NetBSD: distinfo,v 1.70 2020/06/09 00:25:19 taca Exp $ 1$NetBSD: distinfo,v 1.70.2.1 2020/07/29 19:39:44 bsiegert Exp $
2 2
3SHA1 (roundcubemail-1.4.6-complete.tar.gz) = 44961ef62bb9c9875141ca34704bbc7d6f36373d 3SHA1 (roundcubemail-1.4.7-complete.tar.gz) = 49f194d25ac7b9bf175bd52285bb61cde7baed44
4RMD160 (roundcubemail-1.4.6-complete.tar.gz) = 51e323bf7def448b55f57b9279745b5779690ab3 4RMD160 (roundcubemail-1.4.7-complete.tar.gz) = bae742e12b0df75776ceb91c482eaffe0fd512d7
5SHA512 (roundcubemail-1.4.6-complete.tar.gz) = e86763ced58cfa8174f71d33ae45cd62f26a58853b9361b800003fa5bf883a4106c957f66b6b17b03172a3ee595ca74d7c19ac38e449a23377defd77cf555742 5SHA512 (roundcubemail-1.4.7-complete.tar.gz) = d668075c1fb1ac48931a82ca67b4ebeed6f1d1e82a336901f79967cb2eb91979fc7bb46d4895558f8e64f89f963002efc7c1ad23b93c52a252ce1a7aa04b678a
6Size (roundcubemail-1.4.6-complete.tar.gz) = 7031573 bytes 6Size (roundcubemail-1.4.7-complete.tar.gz) = 7031947 bytes
7SHA1 (patch-af) = 7f29b0310a2a6b2e71858787e08b025e30d8bd12 7SHA1 (patch-af) = 7f29b0310a2a6b2e71858787e08b025e30d8bd12
8SHA1 (patch-config_config.inc.php.sample) = 92a48a97b16fe3f5f4b9441fce762a559d8daca7 8SHA1 (patch-config_config.inc.php.sample) = 92a48a97b16fe3f5f4b9441fce762a559d8daca7
9SHA1 (patch-program_lib_Roundcube_rcube__mime.php) = b1e9479d575b7fd61c413e2b76ee36c06ece7a5c 9SHA1 (patch-program_lib_Roundcube_rcube__mime.php) = b1e9479d575b7fd61c413e2b76ee36c06ece7a5c

cvs diff -r1.19 -r1.19.2.1 pkgsrc/mail/roundcube-plugin-password/distinfo (expand / switch to unified diff)

--- pkgsrc/mail/roundcube-plugin-password/distinfo 2020/06/09 00:25:19 1.19
+++ pkgsrc/mail/roundcube-plugin-password/distinfo 2020/07/29 19:39:44 1.19.2.1
@@ -1,7 +1,7 @@ @@ -1,7 +1,7 @@
1$NetBSD: distinfo,v 1.19 2020/06/09 00:25:19 taca Exp $ 1$NetBSD: distinfo,v 1.19.2.1 2020/07/29 19:39:44 bsiegert Exp $
2 2
3SHA1 (roundcubemail-1.4.6-complete.tar.gz) = 44961ef62bb9c9875141ca34704bbc7d6f36373d 3SHA1 (roundcubemail-1.4.7-complete.tar.gz) = 49f194d25ac7b9bf175bd52285bb61cde7baed44
4RMD160 (roundcubemail-1.4.6-complete.tar.gz) = 51e323bf7def448b55f57b9279745b5779690ab3 4RMD160 (roundcubemail-1.4.7-complete.tar.gz) = bae742e12b0df75776ceb91c482eaffe0fd512d7
5SHA512 (roundcubemail-1.4.6-complete.tar.gz) = e86763ced58cfa8174f71d33ae45cd62f26a58853b9361b800003fa5bf883a4106c957f66b6b17b03172a3ee595ca74d7c19ac38e449a23377defd77cf555742 5SHA512 (roundcubemail-1.4.7-complete.tar.gz) = d668075c1fb1ac48931a82ca67b4ebeed6f1d1e82a336901f79967cb2eb91979fc7bb46d4895558f8e64f89f963002efc7c1ad23b93c52a252ce1a7aa04b678a
6Size (roundcubemail-1.4.6-complete.tar.gz) = 7031573 bytes 6Size (roundcubemail-1.4.7-complete.tar.gz) = 7031947 bytes
7SHA1 (patch-plugins_password_helpers_passwd-expect) = 15e427a3c90bf7c0437a023b3f099abb5a139165 7SHA1 (patch-plugins_password_helpers_passwd-expect) = 15e427a3c90bf7c0437a023b3f099abb5a139165