Page 1 of 1

roundcube Security update 1.6.4 released Info

Posted: Fri 27. Oct 2023, 16:44
by Speddy
Published: 16 October 2023

Tags: releases updates security
We just published a security update to the version 1.6 of Roundcube Webmail. It provides a fix to a recently reported XSS vulnerability:

Fix cross-site scripting (XSS) vulnerability in handling of SVG in HTML messages (#9168) reported separately by Matthieu Faou (ESET) and Denys Klymenko.
See the full changelog in the release notes in the release notes on the Github download page.

We strongly recommend to update all productive installations of Roundcube 1.6.x with this new version.

https://roundcube.net/news/2023/10/16/s ... 4-released

Re: roundcube Security update 1.6.4 released Info

Posted: Fri 27. Oct 2023, 16:48
by Jolinar
Liest du auch hier im Forum, bevor du Beiträge verfaßt...?
viewtopic.php?t=12749

Re: roundcube Security update 1.6.4 released Info

Posted: Fri 27. Oct 2023, 16:49
by mhagge
See: viewtopic.php?t=12749 (It is in German, but I think read / translatable)

Re: roundcube Security update 1.6.4 released Info

Posted: Fri 27. Oct 2023, 16:53
by Jolinar
mhagge wrote: Fri 27. Oct 2023, 16:49 See: viewtopic.php?t=12749 (It is in German, but I think read / translatable)
Er schreibt sonst auch deutsch ;)

Re: roundcube Security update 1.6.4 released Info

Posted: Fri 27. Oct 2023, 16:57
by mhagge
Stimmt - ich war vom guten im Menschen ausgegangen und dachte, dass es evtl. an Deutsch/Englisch liegt, dass der Thread vorher nicht aufgefallen war

Re: roundcube Security update 1.6.4 released Info  [SOLVED]

Posted: Mon 30. Oct 2023, 12:11
by Alexander
-> Fixed mit KeyHelp 23.2.1 und Roundcube 1.6.4.