Dear subscribers
We just published updates to all stable versions 1.x delivering important
bug fixes and improvements which we picked from the upstream branch.
The updates primarily fix a recently discovered vulnerability in the
virtualmin and sasl drivers of the password plugin (CVE-2017-8114). More
details about this vulnerability will be published soon by the reporter.
Security-wise the update is therefore only relevant for those installations
of Roundcube using the password plugin with either one of these drivers.
See the full changelog for the according version in the release notes on
the Github download pages:
https://github.com/roundcube/roundcubemail/releases/tag/1.2.5https://github.com/roundcube/roundcubemail/releases/tag/1.1.9https://github.com/roundcube/roundcubemail/releases/tag/1.0.11
All versions are considered stable and we recommend to update all
productive installations of Roundcube with either of these versions.
As usual, don’t forget to backup your data before updating!
Kind regards,
Thomas
Dear subscribers
We proudly announce that the feature-complete release candidate for the
next major version 1.3 of Roundcube webmail is now available for final
testing.
After dropping support for older browsers and PHP versions and adding some
new features like the widescreen layout, the release candidate finalizes
that work and also fixes two security issues (updates for stable versions
will follow) plus adds improvements to the Managesieve and Enigma plugins.
We also slightly polished the Larry theme to make it look a little less
2010 :-)
Although the default theme still doesn’t work on mobile devices, a fully
responsive skin is currently being worked on.
As a reminder: if you’re installing the dependent package or run Roundcube
directly from source, you now need to install the removed 3rd party
javascript modules by executing the following install script:
$ bin/install-jsdeps.sh
With the upcoming stable release of 1.3.0 the old 1.x series will only
receive important security fixes.
As usual, see the complete Changelog in our wiki [1] and download the new
packages from https://roundcube.net/download.
Please note that this is a release candidate and we recommend to test it on
a separate environment. And don’t forget to backup your data before
installing it.
Kind regards,
Thomas
[1] https://github.com/roundcube/roundcubemail/wiki/Changelog
Dear subscribers
We just recently published a security update to the LTS version 1.0. It
contains some important fixes and improvements we backported from the
master version. See the details in the release notes [1].
This release is considered stable and we recommend to update all productive
installations of Roundcube 1.0.x with this version if you're unable to
upgrade to a more recent series. Download it from GitHub via
https://roundcube.net/download.
As usual, don’t forget to backup your data before updating!
Best,
Thomas
[1] https://github.com/roundcube/roundcubemail/releases/tag/1.0.10