We’re pleased to announce an update for the roundcubemail packages, version 1.4.9.
This update is accumulated of version 1.4.6, 1.4.7, 1.4.8 and 1.4.9. It is a bugfix and enhancement release for Kolab 16, available for Red Hat Enterprise Linux 7, CentOS 7, Debian 8, Debian 9, Ubuntu 16.04, Ubuntu 18.04 and for Plesk Premium Email version 16 for Red Hat Enterprise Linux 7, CentOS 7, Debian 8, Debian 9, Ubuntu 16.04 and Ubuntu 18.04.
This package updates Roundcubemail to the upstream version 1.4.9. Among other issue, these listed here has been fixed..
roundcubemail-1.4.6:
- A defect led to spurious errors in the log when extracting required plugins from composer.json. This is fixed
- The database setup description is now compatible with MySQL 8
- A regression in jsevent driver gave problem with the Markasjunk plugin. This is fixed
- A defect caused missing flag indication on collapsed thread in Larry and Elastic. This is fixed
- The default keyserver is now keys.openpgp.org
- Mailvelope: Use sender’s address to find pubkeys to check signatures
- Mailvelope: Encrypt button was hidden in Elastic. This is fixed
- Fix error when user-configured skin does not exist anymore
- Elastic: An issue in the aspect ratio of a contact photo in mail preview was fixed
- A defect prevented some PDF files to be attached in forwarded mails. This is fixed
- Security: A couple of XSS issues in Installer were fixed
- Security: An XSS issue in the template object ‘username’ was fixed
- Security: Improvement of the fix for CVE-2020-12641
- Security: Defect made cross-site scripting (XSS) via malicious XML attachment possible. This is fixed
roundcubemail-1.4.7:
- Subfolders of special folders could have been duplicated on folder list. This was fixed
- Maximum size of contact jobtitle and department fields was increased to 128 characters
- Fix missing newline after the logged line when writing to stdout
- Context menu (‘paste’) on the recipient input was broken. This was fixed
- Fix problem with forwarding inline images attached to messages with no HTML part
- Fix problem with handling attached images with same name when using database_attachments/redundant_attachments
- Security: Fix cross-site scripting (XSS) via HTML messages with malicious svg/namespace
roundcubemail-1.4.8:
- Managesieve: Fix too-small input field in Elastic when using custom headers
- Fix support for an error as a string in message_before_send hook
- Elastic: Fix redundant scrollbar in plain text editor on mail reply
- Elastic: Fix deleted and replied+forwarded icons on messages list
- Managesieve: Allow angle brackets in out-of-office message body
- Fix bug in conversion of email addresses to mailto links in plain text messages
- Fix format=flowed formatting on plain text part derived from the HTML content
- Fix incorrect rewriting of internal links in HTML content
- Fix handling links without defined protocol
- Fix paging of search results on IMAP servers with no SORT capability
- Fix detecting special folders on servers with both SPECIAL-USE and LIST-STATUS
- Security: Fix potential XSS issue in HTML editor of the identity signature input
- Security: Fix cross-site scripting (XSS) via HTML messages with malicious svg content [CVE-2020-16145]
- Security: Fix cross-site scripting (XSS) via HTML messages with malicious math content
roundcubemail-1.4.9:
- Fix HTML editor in latest Chrome 85.0.4183.102, update to TinyMCE 4.9.11
- Add missing localization for some label/legend elements in userinfo plugin
- Fix importing birthday dates from Gmail vCards (BDAY:YYYYMMDD)
- Fix restoring Cc/Bcc fields from local storage
- Fix jstz.min.js installation, bump version to 1.0.7
- Fix incorrect PDO::lastInsertId() use in sqlsrv driver
- Fix link to closure compiler in bin/jsshrink.sh script
- Fix bug where some parts of a message could have been missing in a reply/forward body
- Fix empty space on mail printouts in Chrome
- Fix empty output from HTML5 parser when content contains XML tag
- Fix scroll jump on key press in plain text mode of the HTML editor
- Fix so autocompletion list does not hide on scroll inside it