Software Update: Roundcube Webmail 1.3.10

Spread the love

RoundCube Webmail is a web application that behaves like an imap client. For example, it is used by various hosters to offer webmail functionality. It includes mime and html support, address books, search capabilities and a spell checker. This web application is written in PHP and requires a MySQL, MSSQL, SQLite or Postgres database to store its data. For more information, please refer to this page. The developers have released version 1.3.10 with the following announcement and list of changes:

Roundcube Webmail 1.3.10

This is a service release to update the stable version 1.3 of Roundcube Webmail. It contains fixes to several bugs backported from the master branch including minor security fixes around CSS and HTML cleanup. See the complete changelog below. This version in considered stable and we recommend to update all productive installations of Roundcube with it. Please do backup your data before updating!

CHANGELOG

  • Managesieve: Fix so “Create filter” option does not show up when Filters menu is disabled (#6723)
  • Enigma: Fix bug where revoked users/keys were not greyed out in key info
  • Enigma: Fix error message when trying to encrypt with a revoked key (#6607)
  • Enigma: Fix “decryption oracle” bug [CVE-2019-10740] (#6638)
  • Fix compatibility with kolab/net_ldap3 > 1.0.7 (#6785)
  • Fix bug where bmp images couldn’t be displayed on some systems (#6728)
  • Fix bug in parsing vCard data using PHP 7.3 due to an invalid regexp (#6744)
  • Fix bug where bold/strong text was converted to upper-case on html-to-text conversion (6758)
  • Fix bug in rcube_utils::parse_hosts() where %t, %d, %z could return only tld (#6746)
  • Fix bug where Next/Prev button in mail view didn’t work with multi-folder search result (#6793)
  • Fix bug where selection of columns on messages list wasn’t working
  • Fix bug in converting multi-page Tiff images to Jpeg (#6824)
  • Fix wrong messages order after returning to a multi-folder search result (#6836)
  • Fix PHP 7.4 deprecation: implode() wrong parameter order (#6866)
  • Fix bug where it was possible to bypass the position:fixed CSS check in received messages (#6898)
  • Fix bug where some strict remote URIs in url() style were unintentionally blocked (#6899)
  • Fix bug where it was possible to bypass the CSS jail in HTML messages using :root pseudo-class (#6897)
  • Fix bug where it was possible to bypass href URI check with data:application/xhtml+xml URIs (#6896)

Version number 1.3.10
Release status Final
Operating systems script language
Website Roundcube Webmail
Download
License type GPL
You might also like