mail-client/roundcube: Fix Multiple Vulnerabilities
authorAaron W. Swenson <titanofold@gentoo.org>
Sun, 29 May 2016 17:35:04 +0000 (13:35 -0400)
committerAaron W. Swenson <titanofold@gentoo.org>
Sun, 29 May 2016 17:36:08 +0000 (13:36 -0400)
commit4d31c895c86b85f0fec9effbaf37b55c8a2229fb
tree730f3754166be16c5772578fb793770139e97331
parentebc8636204b9537e74f74b1c7c8c51a2415edf88
mail-client/roundcube: Fix Multiple Vulnerabilities

Many security issues/enhancements are resolved with this release. The
most significant being:

* Fix (again) security issue in DBMail driver of password plugin (CVE-2015-2181)
* Fix path traversal vulnerability in setting a skin (CVE-2015-8770)
* Fix XSS issue in SVG images handling
* Fix XSS issue in href attribute on area tag

You can find the complete list of changes in the included CHANGELOG or at:
https://github.com/roundcube/roundcubemail/wiki/Changelog

Bug: 580746, 584200, 584098

Package-Manager: portage-2.2.26
mail-client/roundcube/Manifest
mail-client/roundcube/roundcube-1.2.0.ebuild [new file with mode: 0644]