Hello Roundcube users
We just published a new release which fixes a recently reported XSS vulnerability as an update to the stable 0.5 branch. Please update your installations with this new version or patch them with the fix which is also published in the downloads section or our sourceforge.net page [1].
And stay tuned, 0.6-beta is on the way with lots of new features ;-)
~Thomas
[1] https://sourceforge.net/projects/roundcubemail/files/roundcubemail/0.5.4/ _______________________________________________ List info: http://lists.roundcube.net/dev/ BT/aba52c80
0.5.4 has a problem. I notified Thomas, and I'm sure it'll get fixed soon. Until that time, I would not download/install 0.5.4 as it will break roundcube.
Cor
List info: http://lists.roundcube.net/dev/ BT/aba52c80
On Fri, 12 Aug 2011 23:12:43 +0200, Cor Bosman wrote:
0.5.4 has a problem. I notified Thomas, and I'm sure it'll get fixed soon. Until that time, I would not download/install 0.5.4 as it will break roundcube.
Cor
List info: http://lists.roundcube.net/dev/ BT/926192a9
i updated my platform with no error
The function rcube_label_exists() is used in 0.5.4, while it doesn't exist. It only exists in 0.6. This causes problems in certain parts of roundcube. I see a blank page when I logout for instance.
Cor
List info: http://lists.roundcube.net/dev/ BT/aba52c80
Thanks for the info. Can you share the problem with the devs?
-- Victor Benincasa
On Fri, Aug 12, 2011 at 6:12 PM, Cor Bosman cor@xs4all.nl wrote:
0.5.4 has a problem. I notified Thomas, and I'm sure it'll get fixed soon. Until that time, I would not download/install 0.5.4 as it will break roundcube.
Cor
List info: http://lists.roundcube.net/dev/ BT/a2aebea3
List info: http://lists.roundcube.net/dev/ BT/aba52c80
Sure, function rcube_label_exists() is missing from 0.5.4, but it is used anyways resulting in php errors and blank pages. I guess if one wanted to upgrade to fix the XSS bugs while a new version is being prepared, one could copy the functions rcube_label_exists() and text_exists() from 0.6.
regards,
Cor
List info: http://lists.roundcube.net/dev/ BT/aba52c80
Hello again
I'm very sorry for the inconvenience but the 0.5.4 package which we have published yesterday was incomplete and some of your already found out. The packages are now updated so please go and re-download it again. Make sure that the checksum od the downloaded file is a4a401b87a89eabd5e113d9e2fe2ea84 (MD5) or d3f4155edf9ef276a948d7b004a7be8890524a54 (SHA1).
Again, I'm very sorry for that! Will test better when releasing.
Best regards, Thomas
On Fri, Aug 12, 2011 at 22:12, Thomas Bruederli thomas@roundcube.net wrote:
Hello Roundcube users
We just published a new release which fixes a recently reported XSS vulnerability as an update to the stable 0.5 branch. Please update your installations with this new version or patch them with the fix which is also published in the downloads section or our sourceforge.net page [1].
And stay tuned, 0.6-beta is on the way with lots of new features ;-)
~Thomas
[1] https://sourceforge.net/projects/roundcubemail/files/roundcubemail/0.5.4/
List info: http://lists.roundcube.net/dev/ BT/aba52c80
Hi Thomas
Thanks for fixing that. Could you pls also update the v0.5.4 SVN tag? https://svn.roundcube.net/tags/roundcubemail/v0.5.4
Best regards, Philip
Am 13.08.2011 um 11:23 schrieb Thomas Bruederli:
Hello again
I'm very sorry for the inconvenience but the 0.5.4 package which we have published yesterday was incomplete and some of your already found out. The packages are now updated so please go and re-download it again. Make sure that the checksum od the downloaded file is a4a401b87a89eabd5e113d9e2fe2ea84 (MD5) or d3f4155edf9ef276a948d7b004a7be8890524a54 (SHA1).
Again, I'm very sorry for that! Will test better when releasing.
Best regards, Thomas
On Fri, Aug 12, 2011 at 22:12, Thomas Bruederli thomas@roundcube.net wrote:
Hello Roundcube users
We just published a new release which fixes a recently reported XSS vulnerability as an update to the stable 0.5 branch. Please update your installations with this new version or patch them with the fix which is also published in the downloads section or our sourceforge.net page [1].
And stay tuned, 0.6-beta is on the way with lots of new features ;-)
~Thomas
[1] https://sourceforge.net/projects/roundcubemail/files/roundcubemail/0.5.4/
RoundCube Announce mailing list Announce@lists.roundcube.net http://lists.roundcube.net/mailman/listinfo/announce BT/e4a7842d
List info: http://lists.roundcube.net/dev/ BT/aba52c80