-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 14 Dec 2025 11:51:43 +0100 Source: roundcube Binary: roundcube roundcube-core roundcube-mysql roundcube-pgsql roundcube-plugins roundcube-sqlite3 Architecture: all Version: 1.6.12+dfsg-0+deb13u1 Distribution: trixie-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Guilhem Moulin Description: roundcube - skinnable AJAX based webmail solution for IMAP servers - metapack roundcube-core - skinnable AJAX based webmail solution for IMAP servers roundcube-mysql - metapackage providing MySQL dependencies for RoundCube roundcube-pgsql - metapackage providing PostgreSQL dependencies for RoundCube roundcube-plugins - skinnable AJAX based webmail solution for IMAP servers - plugins roundcube-sqlite3 - metapackage providing SQLite dependencies for RoundCube Closes: 1122899 Changes: roundcube (1.6.12+dfsg-0+deb13u1) trixie-security; urgency=high . * New upstream security and bugfix release (closes: #1122899). + Fix CVE-2025-68461: Cross-Site-Scripting vulnerability via SVG's animate tag. + Fix CVE-2025-68460: Information Disclosure vulnerability in the HTML style sanitizer. * Refresh d/patches. * d/gbp.conf: Set debian-branch=debian/trixie. * Salsa CI: Set RELEASE=trixie, disable reprotest and lintian jobs. Checksums-Sha1: e63c9e3d52769af954e6531d3f7419aadb603f76 4488344 roundcube-core_1.6.12+dfsg-0+deb13u1_all.deb 425794df8b67157a23a69bd6211edb0ae696a7b9 98560 roundcube-mysql_1.6.12+dfsg-0+deb13u1_all.deb 186c962dc8d3f2272e0c6002f229601f4ab3528e 98536 roundcube-pgsql_1.6.12+dfsg-0+deb13u1_all.deb 01320cdea9a531d2e94bcc3e555d8c6356f89f4e 780608 roundcube-plugins_1.6.12+dfsg-0+deb13u1_all.deb 3184e463dbce899e49256103752b00335cf5ddbe 98508 roundcube-sqlite3_1.6.12+dfsg-0+deb13u1_all.deb 5680372216806e3c96ee632ea29912a9f3f11245 13754 roundcube_1.6.12+dfsg-0+deb13u1_all-buildd.buildinfo d8dda25898f20ca682c24aa690457d8326cfff3d 1296 roundcube_1.6.12+dfsg-0+deb13u1_all.deb Checksums-Sha256: 3241263cd8980bd9f91259dd88b42ae9cbafcbc39fc439d20800b1f592cc1fca 4488344 roundcube-core_1.6.12+dfsg-0+deb13u1_all.deb a4943cc219b6d2febc55dc8b9489319a8f1903785d0aa372b837a5b5572d67fd 98560 roundcube-mysql_1.6.12+dfsg-0+deb13u1_all.deb f3c58ffec4319ff99d63c0858c65461ab1547887e6e2dbe9f51179e1d5cf6eee 98536 roundcube-pgsql_1.6.12+dfsg-0+deb13u1_all.deb d746f4db035903eadfdcec9b8ced54c60c05841a992dd2efb307cd882d349e31 780608 roundcube-plugins_1.6.12+dfsg-0+deb13u1_all.deb 215c9f345f11545f2688ac4cd7bda8ea9ccfd4dd2d4dabb1d3f22b4f15ee5e2f 98508 roundcube-sqlite3_1.6.12+dfsg-0+deb13u1_all.deb 974c05f9aeb4f3d82e416f9a68084a68f0672063795154bb6ac0dfc67e1d4348 13754 roundcube_1.6.12+dfsg-0+deb13u1_all-buildd.buildinfo f33ca6d1013453965b5433db309471c3de27cb31c82789474035f213e4ed2f30 1296 roundcube_1.6.12+dfsg-0+deb13u1_all.deb Files: dc8d034252e3b2fad6ba29432f0b1580 4488344 web optional roundcube-core_1.6.12+dfsg-0+deb13u1_all.deb 69c284b18961d393bef7f0c0e7e29e74 98560 web optional roundcube-mysql_1.6.12+dfsg-0+deb13u1_all.deb 3b5399c9f8db773532d09249effe9e09 98536 web optional roundcube-pgsql_1.6.12+dfsg-0+deb13u1_all.deb 4a039727d6b013cdb9c1bc93afffebfc 780608 web optional roundcube-plugins_1.6.12+dfsg-0+deb13u1_all.deb 8874236410fa89e9a62cf0c84acf1839 98508 web optional roundcube-sqlite3_1.6.12+dfsg-0+deb13u1_all.deb 372c748c87cbd588e9bb4f1665e3825a 13754 web optional roundcube_1.6.12+dfsg-0+deb13u1_all-buildd.buildinfo 818b7deb9e777fbb3f608153aaabe0d0 1296 web optional roundcube_1.6.12+dfsg-0+deb13u1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEj4Fym5GgeZdPqKhrJm69HxMTN+oFAmlEeWMACgkQJm69HxMT N+qSpQ//fCe9AjjfVNq6YFVibQwGBFcrZQJDFKP+HsQEEMG54fTtxnuC+jqAUEc3 Ygnx7UrZbG5J7KXFSSdNG8aJAdHFthc6YFbOdA73nFspGp64zyJ5WkfCsEQh8TZX Ce1900I+1AomEGGOgkGb18gB7tjobLYGn6AYTp+f3iI88FFOvZfWjE5BPmNqN/Pt RTodttxIeAe89KTwpfrAzX3pZZpDZh3AYkLzQ5CcBj5oJBs6G/nxMf+myFA4sisr obooHnLa5SmLoHw0Yuypkgkj7+HiKNxZuGpMw2fJR/ScR3f9cdrnCtUw79Qxthrs gG9U6wzMAhQNpqCp+NdVy+sTg98AewaoV2K7mRR7K0C+r4Nx5YFGjNuQwyBEMVBy 5Eq168QhhikSOtGrS1OGm6dkh4MjF0DYBk4yk4LfCE7WHBHXPrwKH58N9iw9Cpux osOX2EA7wa5wrtzVKMb3j56dW9FRX/rACPveSB5pdhXM5T9XNuFrRbGp4hwO40lc zNEIYK/LOkEwG8PTgi9MTFgNxmQJ+n2VN/6fhWwuC+/izwweA3aW+pSMw7kfB+G5 50UhaEwqqZ3QqkH3MasqBztnBj57iyGjWCCiSiCbJkDRcl2Eg6pKiQmobndWybX2 Tp01wJf6GOVjJZ6mkYWTBA2Decjay+NV2FijJ4/PpCES6tOTUPE= =dULX -----END PGP SIGNATURE-----