roundcube 1.4.3+dfsg.1-1 source package in Ubuntu
Changelog
roundcube (1.4.3+dfsg.1-1) unstable; urgency=medium * New upstream release. * d/roundcube-core.post*: + Replace tabs with spaces. + Pass flag '-f' to rm(1). * d/roundcube-core.postinst: + Create temporary config file with restricted permissions. Previously the file was created with mode 0644 (minus umask), possibly leaking secrets to a local attacker during a short time window. (The file was, and still is, removed later during the postinst stage.) + If the config file /etc/roundcube/config.inc.php already exists, don't override its ownership or mode. Otherwise (atomically) create it with owner root:www-data and mode 0640, like before. (Closes: #951194) + Honor dpkg-statoverride(1) rules on /var/lib/roundcube/temp and /var/log/roundcube: don't chown/chmod these directories if the local admin has defined overrides. * d/roundcube-core.postrm: + Also remove '.ucf-{new,old,dist}'-suffixed configuration files on purge, as suggested by ucf(1). + Only recursively remove /var/lib/roundcube/temp on purge, not its parent /var/lib/roundcube. Roundcube needs only write access to the temp dir. * d/patches/update_script.patch: Restore patch removed in 1.4.1+dfsg.1-1 to fix the ucf logic. * d/patches/dbconfig-common_support.patch: Use C++ style comment for consistency. -- Guilhem Moulin <email address hidden> Mon, 24 Feb 2020 06:39:10 +0100
Upload details
- Uploaded by:
- Debian Roundcube Maintainers
- Uploaded to:
- Sid
- Original maintainer:
- Debian Roundcube Maintainers
- Architectures:
- all
- Section:
- web
- Urgency:
- Medium Urgency
See full publishing history Publishing
Series | Published | Component | Section | |
---|---|---|---|---|
Focal | release | universe | web |
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
roundcube_1.4.3+dfsg.1-1.dsc | 2.4 KiB | 325bfd9dfe56f34043c6651ce5728ea9b960b58ad145d994c50d5db7f674ea58 |
roundcube_1.4.3+dfsg.1.orig.tar.xz | 2.8 MiB | 143a4c7a076f7efdfe3b03f02b6888f134fb75b9b280477a4bfffa2114e309b7 |
roundcube_1.4.3+dfsg.1-1.debian.tar.xz | 1.2 MiB | 09100c04cd86f2b227114889ba47690d5194500edccd03a3f6a07f6e88eabb40 |
Available diffs
- diff from 1.4.2+dfsg.1-2 to 1.4.3+dfsg.1-1 (200.2 KiB)
No changes file available.
Binary packages built by this source
- roundcube: No summary available for roundcube in ubuntu groovy.
No description available for roundcube in ubuntu groovy.
- roundcube-core: No summary available for roundcube-core in ubuntu groovy.
No description available for roundcube-core in ubuntu groovy.
- roundcube-mysql: No summary available for roundcube-mysql in ubuntu groovy.
No description available for roundcube-mysql in ubuntu groovy.
- roundcube-pgsql: No summary available for roundcube-pgsql in ubuntu groovy.
No description available for roundcube-pgsql in ubuntu groovy.
- roundcube-plugins: No summary available for roundcube-plugins in ubuntu groovy.
No description available for roundcube-plugins in ubuntu groovy.
- roundcube-sqlite3: No summary available for roundcube-sqlite3 in ubuntu groovy.
No description available for roundcube-sqlite3 in ubuntu groovy.