[Kolab-devel] roundcube on obs

hede kolab983 at der-he.de
Sat Jul 4 09:19:49 CEST 2020


On Sat, 4 Jul 2020 08:36:20 +0200 hede <kolab983 at der-he.de> wrote:

> But, as an example, there's CVE-2020-13964 and CVE-2020-13965. Both were fixed with roundcube 1.4.5 - more than a month ago - and roundcube upstream is on 1.4.6 in the meantime. Quite a large part of roundcube was (and AFAIK still is) done by kolab folks, but kolab is still on version 1.4.4 for now.

Btw. - where does the file roundcubemail-1.4.4.14.tar.gz within obs.kolabsys.com come from? I cannot find the corresponding repository. It seems not related to git.kolab.org? Nor does it directly get sourced from upstream!?

Regards 
hede


More information about the devel mailing list