[announce] Horde 3.1.6 (final)

Jan Schneider jan at horde.org
Wed Jan 9 22:31:37 UTC 2008

The Horde Team is pleased to announce the final release of the Horde
Application Framework version 3.1.6.

This is a bugfix release that also improves XSS (cross site scripting)
filters, used for example in HTML message viewers, and fixes privilege
escalations in the Horde API. All users are encouraged to upgrade to this

Many thanks to Secunia for reporting an XSS vulnerability (CVE-2007-6018) and
working with us to test the fixes.

The Horde Application Framework is a modular, general-purpose web application
framework written in PHP. It provides an extensive array of libraries that are
targeted at the common problems and tasks involved in developing modern web

Major changes compared to Horde 3.1.5 are:
    * Fixed privilege escalation in the Horde API.
    * Improved XSS filtering.
    * Fixed locked portal blocks.
    * Further improved webroot detection.
    * Updated Japanese translation.

The full list of changes (from version 3.1.5) can be viewed here:


The Horde 3.1.6 distribution is available from the following locations:


Patches against version 3.1.5 are available at:


Or, for quicker access, download from your nearest mirror:


MD5 sums for the packages are as follows:

    9aebe8ef36bfc16a64513f49750fc2a0  horde-3.1.6.tar.gz
    27dcb33fe79ea8a6be278637989ee568  patch-horde-3.1.5-3.1.6.gz

Have fun!

The Horde Team.

More information about the announce mailing list