From: "Aaron Swenson" <titanofold@gentoo.org>
To: gentoo-commits@lists.gentoo.org
Subject: [gentoo-commits] repo/gentoo:master commit in: mail-client/roundcube/
Date: Sun, 29 May 2016 17:42:12 +0000 (UTC) [thread overview]
Message-ID: <1464543368.4d31c895c86b85f0fec9effbaf37b55c8a2229fb.titanofold@gentoo> (raw)
commit: 4d31c895c86b85f0fec9effbaf37b55c8a2229fb
Author: Aaron W. Swenson <titanofold <AT> gentoo <DOT> org>
AuthorDate: Sun May 29 17:35:04 2016 +0000
Commit: Aaron Swenson <titanofold <AT> gentoo <DOT> org>
CommitDate: Sun May 29 17:36:08 2016 +0000
URL: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=4d31c895
mail-client/roundcube: Fix Multiple Vulnerabilities
Many security issues/enhancements are resolved with this release. The
most significant being:
* Fix (again) security issue in DBMail driver of password plugin (CVE-2015-2181)
* Fix path traversal vulnerability in setting a skin (CVE-2015-8770)
* Fix XSS issue in SVG images handling
* Fix XSS issue in href attribute on area tag
You can find the complete list of changes in the included CHANGELOG or at:
https://github.com/roundcube/roundcubemail/wiki/Changelog
Bug: 580746, 584200, 584098
Package-Manager: portage-2.2.26
mail-client/roundcube/Manifest | 1 +
mail-client/roundcube/roundcube-1.2.0.ebuild | 75 ++++++++++++++++++++++++++++
2 files changed, 76 insertions(+)
diff --git a/mail-client/roundcube/Manifest b/mail-client/roundcube/Manifest
index 894f804..b9a7848 100644
--- a/mail-client/roundcube/Manifest
+++ b/mail-client/roundcube/Manifest
@@ -1,2 +1,3 @@
DIST roundcubemail-1.1.4.tar.gz 3209549 SHA256 539a11ed38838b221f8139b193d9762638f155c7b0ea9391315865896be16852 SHA512 18c2422d65292cd13bc4ce592e8490cc0a9d3e9551ac4d188db93eb989525af7ccf519642dd2e68a7380ab0d0d4ad4f999af2b7e99da75d88274743949b42f8a WHIRLPOOL c3e310ddb4dc50b46ff28566d030865029364f69db5a3f39be0d37f165c83486a979b4d3ab7d42835baa7ea9506df8947381612403355a628864ecbde1238d02
DIST roundcubemail-1.2-beta.tar.gz 3421215 SHA256 b7ab853c0a6e52641c851624c4405ce49643553b76c1f50b02b413cb7954fb25 SHA512 454083d6377a07bd418de5593cafb2cc7c0af474e178e322d07adeaa3473ce140a57e6d0a0ee3f58862091bc559596c98d4fb523ef6b9cee91d38064233aade6 WHIRLPOOL 059cd348397a31a3ebf2a6f58acbf832b0722b2740496ae32b4ef036a963a8199fd4f6e718895512ce1fc996da3af65c583f65faef8b817ba94d99fdfda896d3
+DIST roundcubemail-1.2.0.tar.gz 3453543 SHA256 e3b89c2772c2c5990da9bca640bc342f486edf356016cf717e6a1083c822b523 SHA512 3d97e816560830437902ede352e8be81cd93050975934b9dfc86ccf745234119bdf63d5f882fa0d1cc445575c1ea05906a87ae81befdb0bbb38002433e4de199 WHIRLPOOL f9b14ffb2520cd7eda798eb96ec8547af9f5b8d288605d5d777d126cddb3f531f53887ae9bd9b16be7bf194e87165ff48722885328c6dab0d1c1a0ee589817c4
diff --git a/mail-client/roundcube/roundcube-1.2.0.ebuild b/mail-client/roundcube/roundcube-1.2.0.ebuild
new file mode 100644
index 0000000..b3e54be
--- /dev/null
+++ b/mail-client/roundcube/roundcube-1.2.0.ebuild
@@ -0,0 +1,75 @@
+# Copyright 1999-2016 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Id$
+
+EAPI=6
+
+inherit webapp
+
+MY_PN=${PN}mail
+MY_P=${MY_PN}-${PV/_/-}
+
+DESCRIPTION="A browser-based multilingual IMAP client with an application-like user interface"
+HOMEPAGE="http://roundcube.net"
+SRC_URI="https://github.com/${PN}/${MY_PN}/releases/download/${PV/_/-}/${MY_P}.tar.gz"
+
+# roundcube is GPL-licensed, the rest of the licenses here are
+# for bundled PEAR components, googiespell and utf8.class.php
+LICENSE="GPL-3 BSD PHP-2.02 PHP-3 MIT public-domain"
+KEYWORDS="~amd64 ~arm ~hppa ~ppc ~ppc64 ~sparc ~x86"
+
+IUSE="enigma ldap managesieve mysql postgres sqlite ssl spell"
+REQUIRED_USE="|| ( mysql postgres sqlite )"
+
+# this function only sets DEPEND so we need to include that in RDEPEND
+need_httpd_cgi
+
+RDEPEND="
+ ${DEPEND}
+ >=dev-lang/php-5.3.7[crypt,filter,gd,iconv,json,ldap?,pdo,postgres?,session,sockets,sqlite?,ssl?,unicode,xml]
+ >=dev-php/PEAR-Auth_SASL-1.0.6
+ >=dev-php/PEAR-Mail_Mime-1.8.9
+ >=dev-php/PEAR-Mail_mimeDecode-1.5.5
+ >=dev-php/PEAR-Net_IDNA2-0.1.1
+ >=dev-php/PEAR-Net_SMTP-1.6.2
+ virtual/httpd-php
+ enigma? ( >=dev-php/PEAR-Crypt_GPG-1.2.0 app-crypt/gnupg )
+ ldap? ( >=dev-php/PEAR-Net_LDAP2-2.0.12 )
+ managesieve? ( >=dev-php/PEAR-Net_Sieve-1.3.2 )
+ mysql? ( || ( dev-lang/php[mysql] dev-lang/php[mysqli] ) )
+ spell? ( dev-lang/php[curl,spell] )
+"
+
+S=${WORKDIR}/${MY_P}
+
+src_install() {
+ webapp_src_preinst
+ dodoc CHANGELOG INSTALL README.md UPGRADING
+
+ insinto "${MY_HTDOCSDIR}"
+ doins -r [[:lower:]]* SQL
+ doins .htaccess
+
+ webapp_serverowned "${MY_HTDOCSDIR}"/logs
+ webapp_serverowned "${MY_HTDOCSDIR}"/temp
+
+ webapp_configfile "${MY_HTDOCSDIR}"/config/defaults.inc.php
+ webapp_postupgrade_txt en "${FILESDIR}/POST-UPGRADE.txt"
+ webapp_src_install
+}
+
+pkg_postinst() {
+ webapp_pkg_postinst
+
+ ewarn
+ ewarn "When upgrading from <= 0.9, note that the old configuration files"
+ ewarn "named main.inc.php and db.inc.php are deprecated and should be"
+ ewarn "replaced with one single config.inc.php file."
+ ewarn
+ ewarn "Run the ./bin/update.sh script to convert those"
+ ewarn "or manually merge the files."
+ ewarn
+ ewarn "The new config.inc.php should only contain options that"
+ ewarn "differ from the ones listed in defaults.inc.php."
+ ewarn
+}
next reply other threads:[~2016-05-29 17:42 UTC|newest]
Thread overview: 149+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-05-29 17:42 Aaron Swenson [this message]
-- strict thread matches above, loose matches on Subject: below --
2024-09-01 18:38 [gentoo-commits] repo/gentoo:master commit in: mail-client/roundcube/ Craig Andrews
2024-09-01 18:38 Craig Andrews
2024-08-05 13:46 Craig Andrews
2024-06-28 10:41 Miroslav Šulc
2024-06-28 10:21 Arthur Zamarin
2024-05-19 16:25 Craig Andrews
2024-05-19 16:25 Craig Andrews
2024-05-19 16:25 Craig Andrews
2024-05-19 16:25 Craig Andrews
2024-05-19 16:25 Craig Andrews
2024-05-19 16:25 Craig Andrews
2024-05-19 16:25 Craig Andrews
2024-05-19 16:25 Craig Andrews
2024-05-19 16:25 Craig Andrews
2024-05-19 16:25 Craig Andrews
2024-02-21 1:29 Craig Andrews
2023-11-05 19:43 Craig Andrews
2023-11-05 19:43 Craig Andrews
2023-10-16 12:47 Craig Andrews
2023-10-16 12:47 Craig Andrews
2023-09-26 15:31 Arthur Zamarin
2023-09-18 12:21 Craig Andrews
2023-09-15 12:29 Craig Andrews
2023-07-02 13:46 Craig Andrews
2023-01-24 14:46 Craig Andrews
2023-01-24 14:46 Craig Andrews
2022-08-17 4:04 Sam James
2022-07-29 13:54 Craig Andrews
2022-06-27 14:00 Craig Andrews
2022-06-13 13:59 Craig Andrews
2022-03-07 16:05 Craig Andrews
2021-12-31 17:07 Craig Andrews
2021-11-29 15:13 Craig Andrews
2021-11-15 13:39 Craig Andrews
2021-10-19 13:39 Craig Andrews
2021-10-19 13:39 Craig Andrews
2021-08-02 0:44 Craig Andrews
2021-07-06 16:27 Craig Andrews
2021-05-18 2:37 Craig Andrews
2021-02-27 10:44 Aaron W. Swenson
2021-02-27 10:07 Sam James
2021-02-08 20:51 Craig Andrews
2021-01-27 3:28 Sam James
2021-01-09 10:36 Sam James
2021-01-08 10:36 Sam James
2020-12-31 14:21 Craig Andrews
2020-12-31 14:21 Craig Andrews
2020-12-31 14:21 Craig Andrews
2020-12-31 14:21 Craig Andrews
2020-12-31 14:21 Craig Andrews
2020-12-15 21:22 Craig Andrews
2020-11-28 19:52 Thomas Deutschmann
2020-08-30 3:17 Sam James
2020-08-29 3:50 Sam James
2020-08-20 19:20 Thomas Deutschmann
2020-07-27 1:48 Sam James
2020-07-27 1:48 Sam James
2020-07-24 3:41 Aaron W. Swenson
2020-07-23 20:40 Aaron W. Swenson
2020-07-17 23:25 Sam James
2020-07-03 13:48 Sergey Popov
2020-06-28 8:02 Sergei Trofimovich
2020-06-28 7:58 Sergei Trofimovich
2020-06-26 20:21 Thomas Deutschmann
2020-06-20 15:45 Thomas Deutschmann
2020-06-12 14:33 Thomas Deutschmann
2020-06-11 18:01 Sergei Trofimovich
2020-05-25 21:33 Sergei Trofimovich
2020-05-14 21:29 Thomas Deutschmann
2020-05-11 10:52 Thomas Deutschmann
2020-05-08 9:54 Aaron W. Swenson
2020-04-20 11:58 Aaron W. Swenson
2020-02-09 22:33 Miroslav Šulc
2019-11-25 2:03 Aaron W. Swenson
2019-10-06 12:45 Thomas Deutschmann
2019-04-04 21:17 Aaron Bauman
2019-02-02 10:11 Sergei Trofimovich
2018-11-26 10:20 Aaron Swenson
2018-11-24 22:01 Sergei Trofimovich
2018-11-17 15:41 Mikle Kolyada
2018-11-05 19:43 Sergei Trofimovich
2018-11-05 18:11 Mikle Kolyada
2018-11-04 19:14 Thomas Deutschmann
2018-11-04 11:00 Aaron Swenson
2018-10-20 12:16 Sergei Trofimovich
2018-10-15 18:12 Markus Meier
2018-09-28 8:12 Mikle Kolyada
2018-09-24 1:50 Thomas Deutschmann
2018-09-19 19:51 Sergei Trofimovich
2018-05-02 12:16 Aaron Swenson
2018-04-30 22:46 Aaron Bauman
2018-04-30 7:50 Agostino Sarubbo
2018-04-27 19:44 Aaron Swenson
2018-04-27 19:41 Aaron Swenson
2018-04-24 19:32 Mikle Kolyada
2018-03-19 20:02 Sergei Trofimovich
2018-03-19 9:25 Sergei Trofimovich
2018-03-14 11:20 Mikle Kolyada
2018-03-13 22:26 Thomas Deutschmann
2018-03-08 21:57 Sergei Trofimovich
2018-01-23 12:05 Aaron Swenson
2018-01-23 11:58 Aaron Swenson
2017-12-07 15:49 Craig Andrews
2017-12-04 12:23 Aaron Swenson
2017-11-19 15:19 Markus Meier
2017-11-11 18:00 Thomas Deutschmann
2017-11-09 17:52 Aaron Swenson
2017-10-18 7:54 Tim Harder
2017-06-19 10:35 Aaron Swenson
2017-06-08 5:08 Markus Meier
2017-06-05 14:30 Thomas Deutschmann
2017-06-05 11:05 Agostino Sarubbo
2017-06-04 21:06 Thomas Deutschmann
2017-04-18 13:16 Aaron Swenson
2017-04-01 10:40 Michael Weber
2017-04-01 10:02 Michael Weber
2017-03-21 10:00 Michael Weber
2017-03-20 12:28 Agostino Sarubbo
2017-03-18 13:34 Thomas Deutschmann
2016-12-23 18:30 Aaron Swenson
2016-12-23 15:06 Markus Meier
2016-12-13 11:30 Agostino Sarubbo
2016-12-13 11:05 Agostino Sarubbo
2016-12-12 23:41 Thomas Deutschmann
2016-10-30 18:07 Aaron Swenson
2016-09-22 18:37 Aaron Swenson
2016-09-22 18:37 Aaron Swenson
2016-07-28 14:15 Sergey Popov
2016-07-28 13:53 Sergey Popov
2016-06-04 5:08 Markus Meier
2016-05-31 9:35 Agostino Sarubbo
2016-05-31 9:30 Agostino Sarubbo
2016-01-21 13:55 Aaron Swenson
2016-01-21 13:20 Agostino Sarubbo
2016-01-20 15:34 Andreas Schuerch
2016-01-17 17:02 Agostino Sarubbo
2016-01-17 14:09 Markus Meier
2016-01-14 18:51 Aaron Swenson
2016-01-07 20:34 Markus Meier
2015-12-29 9:41 Jeroen Roovers
2015-12-26 10:36 Agostino Sarubbo
2015-12-25 18:19 Agostino Sarubbo
2015-12-24 20:11 Agostino Sarubbo
2015-09-01 15:59 Markus Meier
2015-08-26 7:28 Agostino Sarubbo
2015-08-25 7:09 Agostino Sarubbo
2015-08-25 7:09 Agostino Sarubbo
2015-08-25 4:55 Tim Harder
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1464543368.4d31c895c86b85f0fec9effbaf37b55c8a2229fb.titanofold@gentoo \
--to=titanofold@gentoo.org \
--cc=gentoo-commits@lists.gentoo.org \
--cc=gentoo-dev@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox