Commit graph

11 commits

Author SHA1 Message Date
taca
3a0178846b mail/roundcube-plugin-enigma: update to 1.3.7
- Enigma: [EFAIL] Don't decrypt PGP messages with no MDC protection (#6289)
2018-08-09 15:07:01 +00:00
triaxx
f14034107a roundcube-plugin-enigma: update distinfo for 1.3.6 2018-05-16 08:17:31 +00:00
taca
a9fd488ab5 mail/roundcube: update to 1.2.9
RELEASE 1.2.9
-------------
- Fix regression where IMAP commands with '*' uidset argument wasn't working
2018-04-30 06:45:03 +00:00
taca
f4c46566f0 mail/roundcube: update to 1.2.8
This is a security update to the stable version 1.2.  It fixes a recently
reported vulnerability allowing IMAP command injection via a GET parameters.
More details about this are published under CVE-2018-9846.

The second fix is about a missed remote content blocking on HTML messages with
specially crafted image and style tags.

We strongly recommend to update all productive installations of Roundcube
1.2.x.  Please do backup your data before updating!

CHANGELOG

* Fix check_request() bypass in places using get_uids() [CVE-2018-9846]
  (#6238)

* Fix possible IMAP command injection vulnerability [CVE-2018-9846] (#6229)

* Fix security issue in remote content blocking on HTML image and style tags
  (#6178)
2018-04-23 13:54:59 +00:00
taca
ce924953c0 mail/roundcube: update to 1.2.7
Security fix for CVE-2017-16651.

RELEASE 1.2.7
-------------
- Fix rewind(): stream does not support seeking (#5950)
- Fix bug where HTML messages could have been rendered empty on some systems
  (#5957)
- Fix (again) bug where image data URIs in css style were treated as
  evil/remote in mail preview (#5580)
- Managesieve: Fix parsing dot-staffed lines in multiline text (#5838, #5959)
- Fix file disclosure vulnerability caused by insufficient input validation
  [CVE-2017-16651] (#6026)
2017-11-09 01:13:11 +00:00
taca
eedf96b60b Update roundcube-plugin-enigma to 1.2.6.
RELEASE 1.2.6
-------------
- Enigma: Fix compatibility with assets_dir
2017-09-11 13:57:24 +00:00
taca
406711f68b Update roundcube-plugin-enigma to 1.2.5.
Nothing is change except version.
2017-04-28 13:50:10 +00:00
taca
c45e79ddac Update roundcube-plugin-enigma to 1.2.4
RELEASE 1.2.4
-------------
- Enigma: Fix handling of messages with nested PGP encrypted parts (#5634)
- Enigma: Fix PHP fatal error when decrypting a message with invalid signature
  (#5555)
- Enigma: Fix missing require statement for Crypt_GPG_KeyGenerator (#5641)
2017-03-12 13:34:39 +00:00
taca
21c4b221d4 roundcube-plugin-enigma to 1.2.3.
pkgsrc changes:
* Add dependency to security/pear-Crypt_GPG.

other changes:
* Add eu_EU and sq_AL locale.

RELEASE 1.2.3

* Enigma: Fix bug where last records on keys list were hidden (#5461)
* Enigma: Fix key search with keyword containing non-ascii characters (#5459)
2016-12-05 16:15:33 +00:00
taca
0def2d7ce7 Update roundcube-plugin-enigma to 1.2.2.
- Enigma: Add possibility to configure gpg-agent binary location (enigma_pgp_agent)
- Enigma: Fix signature verification with some IMAP servers, e.g. Gmail, DBMail (#5371)
- Enigma: Make recipient key searches case-insensitive (#5434)
2016-10-08 14:42:23 +00:00
taca
0ca479572c Add roundcube-plugin-enigma package version 1.2.1, it is part of
official roundcube.

Enigma Plugin for Roundcube

This plugin adds support for viewing and sending of signed and encrypted
messages in PGP (RFC 2440) and PGP/MIME (RFC 3156) format.

The plugin uses gpg binary on the server and stores all keys
(including private keys of the users) on the server.
Encryption/decryption is done server-side. So, this plugin
is for users that trust the server.
2016-09-13 15:58:57 +00:00