[announce] Turba H3 (2.1.7) (final)

Chuck Hagenbuch chuck at horde.org
Fri Feb 15 16:30:45 UTC 2008


The Horde Team is pleased to announce the final release of the Turba Contact
Manager version H3 (2.1.7).

This is a security release that fixes unchecked access to contacts in
the same SQL table, if the unique key of another user's contact can be
guessed.  All users are encouraged to upgrade to this version.

Turba is the Horde contact management application. It is a production level
address book, and makes heavy use of the Horde framework to provide
integration with IMP and other Horde applications. It supports SQL, LDAP,
Kolab, and IMSP address books.

Major changes compared to the Turba H3 (2.1.6) version are:
    * Fixed unchecked access to contacts in the same SQL table (Bug #6208).

The full list of changes (from version H3 (2.1.6)) can be viewed here:

http://cvs.horde.org/diff.php/turba/docs/CHANGES?r1=1.181.2.114.2.2&r2=1.181.2.114.2.4&ty=h

The Turba H3 (2.1.7) distribution is available from the following locations:

    ftp://ftp.horde.org/pub/turba/turba-h3-2.1.7.tar.gz
    http://ftp.horde.org/pub/turba/turba-h3-2.1.7.tar.gz

Patches against version H3 (2.1.6) are available at:

    ftp://ftp.horde.org/pub/turba/patches/patch-turba-h3-2.1.6-h3-2.1.7.gz
    http://ftp.horde.org/pub/turba/patches/patch-turba-h3-2.1.6-h3-2.1.7.gz

Or, for quicker access, download from your nearest mirror:

    http://www.horde.org/mirrors.php

MD5 sums for the packages are as follows:

    9cde9a44239c852211204112f3d6edfe  turba-h3-2.1.7.tar.gz
    0236aa29dc1140d4e15861afbaf40b35  patch-turba-h3-2.1.6-h3-2.1.7.gz

Have fun!

The Horde Team.


More information about the announce mailing list