Roundcube Update for critical vulnerability

Hi all,

is a roundcube update in the works? Or do we have to update it manually?

See also: https://blog.ripstech.com/2016/roundcube-command-execution-via-email/

Cheers,

Michael

Hi Michael

Many thanks, and I checked our versions running, which are not the very latest.

I’ve let Iw know about this thread for you, so you have credit

Also, I think it maybe hard for own upgrade, as it is in part, connected to Iw-CP, which I know in the past could not be fully completed by users, as there were a difference in databases

I hope that helps a little

Many thanks

John

Thanks John! Let’s hope IW have time to fix this soon.

Hi Michael

Iw rocks, just received this from Jenna :slight_smile:

Many thanks

John

There is a hotfix for that issue in the works, which should be out soon. :slight_smile:

Yes, they rock, that’s good news. THANKS!

Hi Michael
Sorry, the fix is in the latest release candidate now, which was available a few days ago, but just did not have time to update post sorry
Many thanks
John

Hi John,

no Problem, look at the time it took me to answer;-) And it’s would actually IW’s job to inform us, but I am very glad you always help.

One thing though, the roundcube version number in 1260 still shows as 1.1.2. Any idea why?

Cheers,

Michael

Hi Michael

Many thanks, and to be honest, part of a moderator is to keep users informed, where I can I think, so I try hard to do so

I believe it was a hotfix to resolve issue and not a roundcube update, which I’m sure will be along very soon

Many thanks

John