We just published security updates to the 1.6 and 1.5 LTS versions of Roundcube Webmail, as well as a release candidate for coming 1.7. They contain fixes for recently reported set of security vulnerabilities.
## Security fixes
redis/memcache session handler, reported by y0us.
password, reported by flydragon777.
Security Research Team.
reported by nullcathedral.
attribute, reported by nullcathedral.
by nullcathedral.
network hosts, reported by Georgios Tsimpidas (aka Frey), Security Researcher at https://i0.rs/.
See the full changelogs in the release notes on the Github download pages for the updated versions
We strongly recommend to update your productive installations of Roundcube with this new versions.