Commit graph

31 commits

Author SHA1 Message Date
wiz
6eae1297d5 *: recursive bump for perl 5.34 2021-05-24 19:49:01 +00:00
taca
4cc1148138 mail/roundcube: update to 1.4.11
RELEASE 1.4.11
--------------
- Display a nice error informing about no PHP8 support
- Elastic: Fix compatibility with Less v3 and v4 (#7813)
- Fix bug with managesieve_domains in Settings > Forwarding form (#7849)
- Fix errors in MSSQL database update scripts (#7853)
- Security: Fix cross-site scripting (XSS) via HTML messages with
  malicious CSS content
2021-02-09 00:46:41 +00:00
taca
2792d7d76a mail/roundcube: update to 1.4.10
Update roundcube to 1.4.10, including security fix.

RELEASE 1.4.10
--------------
- Fix extra angle brackets in In-Reply-To header derived from mailto: params (#7655)
- Fix folder list issue whan special folder is a subfolder (#7647)
- Fix Elastic's folder subscription toggle in search result (#7653)
- Fix state of subscription toggle on folders list after changing folder state from the search result (#7653)
- Security: Fix cross-site scripting (XSS) via HTML or Plain text messages with malicious content [CVE-2020-35730]
2020-12-28 08:58:10 +00:00
nia
f6dd9d2f87 Revbump packages with a runtime Python dep but no version prefix.
For the Python 3.8 default switch.
2020-12-04 20:44:57 +00:00
taca
e10cd17bed mail/roundcube-plugin-password: reset PKGREVISION
Reset PKGREVSION with updating to 1.4.9.
2020-10-04 06:27:45 +00:00
taca
4faa62071d mail/roundcube: update to 1.4.9
Update roundcube package to 1.4.9.


Roundcube Webmail 1.4.9 (2020-09-27)

This is a service update to the stable version 1.4 of Roundcube Webmail.

It contains fixes and general improvements from our issue tracker, mainly
related to email composition and UI oddities in Elastic skin and with the
TinyMCE richtext editor.  See the full changelog below.

This version is considered stable and we recommend to update all productive
installations of Roundcube with it.

Please do backup your data before updating!

CHANGELOG

* Fix HTML editor in latest Chrome 85.0.4183.102, update to TinyMCE 4.9.11
  (#7615)
* Add missing localization for some label/legend elements in userinfo plugin
  (#7478)
* Fix importing birthday dates from Gmail vCards (BDAY:YYYYMMDD)
* Fix restoring Cc/Bcc fields from local storage (#7554)
* Fix jstz.min.js installation, bump version to 1.0.7
* Fix incorrect PDO::lastInsertId() use in sqlsrv driver (#7564)
* Fix link to closure compiler in bin/jsshrink.sh script (#7567)
* Fix bug where some parts of a message could have been missing in a
  reply/forward body (#7568)
* Fix empty space on mail printouts in Chrome (#7604)
* Fix empty output from HTML5 parser when content contains XML tag (#7624)
* Fix scroll jump on key press in plain text mode of the HTML editor (#7622)
* Fix so autocompletion list does not hide on scroll inside it (#7592)
2020-10-04 06:26:11 +00:00
wiz
00da7815c0 *: bump PKGREVISION for perl-5.32. 2020-08-31 18:06:29 +00:00
taca
a929c817f1 mail/roundcube: update to 1.4.8
Update roundcube to 1.4.8, security release.


RELEASE 1.4.8
-------------
- Security: Fix potential XSS issue in HTML editor of the identity signature input (#7507)
- Managesieve: Fix too-small input field in Elastic when using custom headers (#7498)
- Fix support for an error as a string in message_before_send hook (#7475)
- Elastic: Fix redundant scrollbar in plain text editor on mail reply (#7500)
- Elastic: Fix deleted and replied+forwarded icons on messages list (#7503)
- Managesieve: Allow angle brackets in out-of-office message body (#7518)
- Fix bug in conversion of email addresses to mailto links in plain text messages (#7526)
- Fix format=flowed formatting on plain text part derived from the HTML content (#7504)
- Fix incorrect rewriting of internal links in HTML content (#7512)
- Fix handling links without defined protocol (#7454)
- Fix paging of search results on IMAP servers with no SORT capability (#7462)
- Fix detecting special folders on servers with both SPECIAL-USE and LIST-STATUS (#7525)
- Security: Fix cross-site scripting (XSS) via HTML messages with malicious svg content [CVE-2020-16145]
- Security: Fix cross-site scripting (XSS) via HTML messages with malicious math content
2020-08-10 22:30:41 +00:00
taca
2dc1006b11 mail/roundcube: update to 1.4.7
Update roundcube to 1.4.7.


RELEASE 1.4.7
-------------
- Fix bug where subfolders of special folders could have been duplicated on folder list
- Increase maximum size of contact jobtitle and department fields to 128 characters
- Fix missing newline after the logged line when writing to stdout (#7418)
- Elastic: Fix context menu (paste) on the recipient input (#7431)
- Fix problem with forwarding inline images attached to messages with no HTML part (#7414)
- Fix problem with handling attached images with same name when using database_attachments/redundant_attachments (#7455)
- Security: Fix cross-site scripting (XSS) via HTML messages with malicious svg/namespace
2020-07-07 04:37:26 +00:00
taca
d345e23b1d mail/roundcube: update to 1.14.6
Update roundcube to 1.14.6.


RELEASE 1.4.6
-------------
- Installer: Fix regression in SMTP test section (#7417)
2020-06-09 00:25:19 +00:00
taca
d370564bbb mail/roundcube-plugin-password: update to 1.4.5
Update roundcube-plugin-password to 1.4.5


RELEASE 1.4.5
-------------
- Password: Fix issue with Modoboa driver (#7372)
2020-06-07 22:08:37 +00:00
taca
390973d5fa mail/roundcube-plugin-password: update to 1.4.4
Update roundcube-plugin-password to 1.4.4.

pkgsrc change: add dependecy to lang/tcl-expect.


RELEASE 1.4.3
-------------
- Password: Make chpass-wrapper.py Python 3 compatible (#7135)
2020-04-30 07:11:15 +00:00
taca
42e9bfb830 mail/roundcube-plugin-password: fix runtime problem
Fix roundcube-plugin-password.

* Patch for roundcube-plugin-password had not been applied accidently.
* More changes were required to make it work on *BSD system.

Bump PKGREVISION.
2020-04-26 08:48:23 +00:00
taca
ea4f0e34f6 mail/roundcube-plugin-password: update to 1.4.2
Update roundcube-plugin-password to 1.4.2.

pkgsrc change:

* Use common patches/distinfo directory with roundcube.

RELEASE 1.4.2
-------------
- Password: Fix kpasswd and smb drivers' double-escaping bug (#7092)

RELEASE 1.4-rc2
---------------
- Password: Added ldap_exop driver (#4992)
- Password: Added support for SSHA512 password algorithm (#6805)

RELEASE 1.4-rc1
---------------
- Password: Added 'modoboa' driver (#6361)
- Password: Fix bug where password_dovecotpw_with_method setting could be ignored (#6436)
- Password: Fix bug where new users could skip forced password change (#6434)
- Password: Allow drivers to override default password comparisons (eg new is not same as current) (#6473)
- Password: Allow drivers to override default strength checks (eg allow for 'not the same as last x passwords') (#246)
- Passowrd: Allow drivers to define password strength rules displayed to the user
- Password: Allow separate password saving and strength drivers for use of strength checking services (#5040)
- Password: Add zxcvbn driver for checking password strength (#6479)
- Password: Disallow control characters in passwords
- Password: Add support for Plesk >= 17.8 (#6526)

RELEASE 1.4-beta
----------------
- Password: Support host variables in password_db_dsn option (#5955)
- Password: Automatic virtualmin domain setting, removed password_virtualmin_format option (#5759)
- Password: Added password_username_format option (#5766)
2020-01-14 14:33:16 +00:00
taca
7797f5c2ce mail/roundcube-plugin-password: update to 1.3.10
Update roundcube-plugin-password to 1.3.10.  No changes except version.

pkgsrc change: remove duplicated setting PLUGIN.
2019-09-01 13:10:39 +00:00
taca
260b119658 mail/roundcube: update to 1.3.9
Update roundcube and related pacakges to 1.3.9.

RELEASE 1.3.9
-------------
- Fix TinyMCE download location (#6694)
- Fix bug where a message/rfc822 part without a filename wasn't listed on the attachments list (#6494)
- Fix handling of empty entries in vCard import (#6564)
- Fix bug in parsing some IMAP command responses that include unsolicited replies (#6577)
- Fix PHP 7.2 compatibility in debug_logger plugin (#6586)
- Fix so ANY record is not used for email domain validation, use A, MX, CNAME, AAAA instead (#6581)
- Fix so mime_content_type check in Installer uses files that should always be available (i.e. from program/resources) (#6599)
- Fix missing CSRF token on a link to download too-big message part (#6621)
- Fix bug when aborting dragging with ESC key didn't stop the move action (#6623)
- Fix bug where next row wasn't selected after deleting a collapsed thread (#6655)
2019-04-30 03:58:45 +00:00
maya
f34a8c24a3 PKGREVISION bump for anything using python without a PYPKGPREFIX.
This is a semi-manual PKGREVISION bump.
2019-04-25 07:32:34 +00:00
taca
956b5600fa mail/roundcube-plugin-password: update to 1.3.8
No change except version.
2018-10-28 15:26:35 +00:00
taca
a8d0454b5b mail/roundcube-plugin-password: update to 1.3.7
* No change except version.

Reset PKGREVISION.
2018-08-09 15:08:15 +00:00
taca
a9d7eebb5b mail/roundcube-plugin-password: fix interpreter
* Replace interpreter of perl script.
* Do not set REPLACE_PYTHON but add to it.

Bump PKGREVISION.
2018-05-20 03:54:54 +00:00
taca
8a9673eff3 mail/roundcube-plugin-password: Fix PLIST
Fix PLIST after update to 1.3.6.
2018-05-20 03:50:52 +00:00
triaxx
25330ce124 roundcube-plugin-password: update distinfo for 1.3.6 2018-05-16 08:17:50 +00:00
taca
a9fd488ab5 mail/roundcube: update to 1.2.9
RELEASE 1.2.9
-------------
- Fix regression where IMAP commands with '*' uidset argument wasn't working
2018-04-30 06:45:03 +00:00
taca
f4c46566f0 mail/roundcube: update to 1.2.8
This is a security update to the stable version 1.2.  It fixes a recently
reported vulnerability allowing IMAP command injection via a GET parameters.
More details about this are published under CVE-2018-9846.

The second fix is about a missed remote content blocking on HTML messages with
specially crafted image and style tags.

We strongly recommend to update all productive installations of Roundcube
1.2.x.  Please do backup your data before updating!

CHANGELOG

* Fix check_request() bypass in places using get_uids() [CVE-2018-9846]
  (#6238)

* Fix possible IMAP command injection vulnerability [CVE-2018-9846] (#6229)

* Fix security issue in remote content blocking on HTML image and style tags
  (#6178)
2018-04-23 13:54:59 +00:00
taca
ce924953c0 mail/roundcube: update to 1.2.7
Security fix for CVE-2017-16651.

RELEASE 1.2.7
-------------
- Fix rewind(): stream does not support seeking (#5950)
- Fix bug where HTML messages could have been rendered empty on some systems
  (#5957)
- Fix (again) bug where image data URIs in css style were treated as
  evil/remote in mail preview (#5580)
- Managesieve: Fix parsing dot-staffed lines in multiline text (#5838, #5959)
- Fix file disclosure vulnerability caused by insufficient input validation
  [CVE-2017-16651] (#6026)
2017-11-09 01:13:11 +00:00
taca
efc083c828 Update roundcube-plugin-password to 1.2.6.
No change except version.
2017-09-11 14:00:23 +00:00
taca
1e0e6fb9d0 Update roundcube-plugin-password to 1.2.5 fixing security problem.
RELEASE 1.2.5
-------------
- Password: Fix security issue in virtualmin and sasl drivers [CVE-2017-8114]
2017-04-28 13:51:07 +00:00
taca
0653a11c8d Update roundcube-plugin-password to 1.2.4.
Nothing is changed expect version.
2017-03-12 13:35:21 +00:00
taca
0396a95636 Update roundcube-plugin-password to 1.2.3.
* Add is_IS locale support.
2016-12-05 16:16:16 +00:00
taca
23815770cf Update roundcube-plugin-password to 1.2.2.
None except version.
2016-10-08 14:42:55 +00:00
taca
d6059148a1 Add roundcube-plugin-password package version 1.2.1, it is part of
official roundcube.

Password Plugin for Roundcube

Plugin that adds a possibility to change user password using many
methods (drivers) via Settings/Password tab.
2016-09-13 16:00:15 +00:00