Dear subscribers
We proudly announce the next service release to update the stable version
1.3. It contains fixes to several bugs backported from the master branch
including a security fix mitigating the EFAIL issue recently discovered in
OpenPGP. See the full changelog in the release notes on the Github download
page [1].
This release is considered stable and we recommend to update all productive
installations of Roundcube with this version. Download it from
https://roundcube.net.
And there are more good news ahead: the long awaited responsive theme for
Roundcube, codename "elastic", has now matured and we'll publish a beta
release with the new skin soon. For a quick preview you can already pull
the Docker container roundcube/roundcubemail:elastic which bundles the
current git master version with the elastic theme enabled.
Best,
Alec & Thomas
[1] https://github.com/roundcube/roundcubemail/releases/tag/1.3.7
Dear subscribers
As a follow-up to the recent security update for the stable versions
1.2. and 1.1, we just published a new release to fix a regression that
sneaked in with the IMAP command injection protection. Roundcube
versions 1.2.8. and 1.1.11 unintentionally disable actions that
operate on all selected messages (e.g. mark all as junk).
We therefore recommend to update all productive installations of
Roundcube 1.2.8. and 1.1.11 with these new versions.
https://github.com/roundcube/roundcubemail/releases/tag/1.2.9https://github.com/roundcube/roundcubemail/releases/tag/1.1.12
Best,
Alec & Thomas
Dear subscribers
Following the recent security update for 1.3, here now come the
promised updates for the LTS versions 1.2 and 1.1. They both fix the
recently reported vulnerability allowing IMAP command injection via a
GET parameters. More details about this are published under
CVE-2018-9846.
Another fix included in these updates is about a missed remote content
blocking on HTML messages with specially crafted image and style tags.
See the full changelog in the release notes on the according Github
download pages:
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.8
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.11
and download the packages right from there.
We strongly recommend to update all productive installations of
Roundcube 1.2.x and 1.1.x respectively.
Please do backup your data before updating!
Kind regards
Alec & Thomas
Dear subscribers
We just published a security update to the stable version 1.3. It
primarily fixes a recently reported IMAP command injection
vulnerability caused by insufficient input validation within the
archive plugin. Details about the vulnerability are published under
CVE-2018-9846.
Additionally, we back-ported some minor fixes from the master branch
which improve PHP 7.2 compatibility as well as PGP signing and key
handling for those who use the Enigma plugin.
See the full changelog in the release notes on the Github download page:
https://github.com/roundcube/roundcubemail/releases/tag/1.3.6
We strongly recommend to update all productive installations of
Roundcube with this new version.
Updates for older LTS versions will follow soon.
And as usual: please do backup your data before updating!
Best,
Alec & Thomas
Dear subscribers
We proudly announce a new service release to update the stable version
1.3. It contains fixes to some issues which we backported from the
master branch. One can be called a minor security fix as it fixes
blocking of remote content on specially crafted style tags.
See the full changelog in the release notes on the Github download page [1].
This release is considered stable and we recommend to update all
productive installations of Roundcube with this version. Download it
from https://roundcube.net.
And stay tuned for the upcoming 1.4 beta release which will include a
preview to the new "Elastic" theme.
Apropos: we're still looking for a volunteer designer to do the final
polishing on the new skin. Read about the progress of the Elastic skin
in Alec's blog [2].
Best,
Thomas & Alec
[1] https://github.com/roundcube/roundcubemail/releases/tag/1.3.5
[2] https://kolabian.wordpress.com/tag/elastic/
Dear subscribers
We proudly announce the next service release to update the stable version 1.3.
It contains fixes to several bugs reported by our dear community
members and makes Roundcube now fully compatible with PHP 7.2.
See the full changelog in the release notes [1] on our Github download page.
This release is considered stable and we recommend to update all
productive installations of Roundcube with this version.
Download it from https://roundcube.net/download.
And as usual: please do backup your data before updating!
New: starting with version 1.3.3 we also publish Roundcube releases as
Docker images. The images are still considered BETA and your feedback
with regards to setup, configuration and documentation is much
appreciated.
Best,
Alec & Thomas
[1] https://github.com/roundcube/roundcubemail/releases/tag/1.3.4
Dear subscribers
We just published updates to all stable versions from 1.1.x onwards
delivering fixes for a recently discovered file disclosure
vulnerability in Roundcube Webmail.
Apparently this zero-day exploit is already being used by hackers to
read Roundcube’s configuration files. It requires a valid
username/password as the exploit only works with a valid session. More
details will be published soon under CVE-2017-16651.
The Roundcube series 1.0.x is not affected by this vulnerability but
we nevertheless back-ported the fix in order to protect from yet
unknown exploits.
See the full changelog for the according version in the release notes
on the Github download pages:
https://github.com/roundcube/roundcubemail/releases/tag/1.3.3https://github.com/roundcube/roundcubemail/releases/tag/1.2.7https://github.com/roundcube/roundcubemail/releases/tag/1.1.10https://github.com/roundcube/roundcubemail/releases/tag/1.0.12
We strongly recommend to update all productive installations of
Roundcube with either one of these versions.
In order to check whether your Roundcube installation has been
compromised check the access logs for requests like
?_task=settings&_action=upload-display&_from=timezone
As mentioned above, the file disclosure only works for authenticated
users and by finding such requests in the logs you should also be able
to identify the account used for this unauthorized access. For
mitigation we recommend to change the all credentials to external
services like database or LDAP address books and preferably also the
'des_key' option in your config.
Kind regards
Alec & Thomas
Dear subscribers
We proudly announce the second service release to update the stable version 1.3.
It contains fixes to several bugs reported by you, our dear community
members as well as translation updates synchronized from Transifex.
We also changed the wording for the setting that controls the time
after which an opened message is marked as read. This was previously
only affecting messages being viewed in the preview panel but now
applies to all means of opening a message. That change came with 1.3.0
an apparently confused many users. Some translation work is still
needed here.
See the full changelog in the release notes [1] on our Github download page.
This release is considered stable and we recommend to update all
productive installations of Roundcube with this version.
Download it from https://roundcube.net/download.
And as usual: please do backup your data before updating!
Best,
Alec & Thomas
[1] https://github.com/roundcube/roundcubemail/releases/tag/1.3.2
Dear subscribers
We just published a service and security update to the stable version 1.2.
It contains some important bug fixes and improvements which we picked
from the upstream branch.
See the full changelog in the release notes on the Github download page [1].
This release is considered stable and we recommend to update all
productive 1.2.x installations of Roundcube with this version.
Download it from Github via https://roundcube.net/download.
Please remember to backup your data before updating!
Cheers,
Alec & Thomas
[1] https://github.com/roundcube/roundcubemail/releases/tag/1.2.6
Dear subscribers
We just published the first service release to update the stable
version 1.3 which is the result of some touching-up on the new
features introduced with the 1.3.0 release. For example it brings back
the double-click behavior to open messages which was reduced to the
list-only view. Or because the switch to change the mail view layout
was a bit hidden, we also added it to the preferences section.
The update also includes fixes to reported bugs and one potential XSS
vulnerability as well as optimizations to smoothly run on the latest
version of PHP.
See the full changelog in the release notes [1] on the Github download page.
This release is considered stable and we recommend to update all
productive installations of Roundcube with this version.
Download it from https://roundcube.net/download.
Please do backup your data before updating!
Best,
Alec & Thomas
[1] https://github.com/roundcube/roundcubemail/releases/tag/1.3.1