[announce] Horde Groupware 1.0.5 (final)

Jan Schneider jan at horde.org
Sat Mar 8 12:36:26 UTC 2008


The Horde Team is pleased to announce the final release of the Horde Groupware
version 1.0.5.

This is a security release that closes a file inclusion vulnerability through
abuse of the theme preference. All users are encouraged to upgrade to this
version.

Horde Groupware is a free, enterprise ready, browser based collaboration
suite. Users can manage and share calendars, contacts, tasks and notes with the
standards compliant components from the Horde Project.

Major changes compared to Horde Groupware 1.0.4 are:
    * Fix arbitrary file inclusion through abuse of the theme preference.

The full list of changes (from version 1.0.4) can be viewed here:

http://cvs.horde.org/diff.php/groupware/docs/groupware/CHANGES?r1=1.17.2.2&r2=1.17.2.3&ty=h

The Horde Groupware 1.0.5 distribution is available from the following locations:

    ftp://ftp.horde.org/pub/horde-groupware/horde-groupware-1.0.5.tar.gz
    http://ftp.horde.org/pub/horde-groupware/horde-groupware-1.0.5.tar.gz

Patches against version 1.0.4 are available at:

    ftp://ftp.horde.org/pub/horde-groupware/patches/patch-horde-groupware-1.0.4-1.0.5.gz
    http://ftp.horde.org/pub/horde-groupware/patches/patch-horde-groupware-1.0.4-1.0.5.gz

Or, for quicker access, download from your nearest mirror:

    http://www.horde.org/mirrors.php

MD5 sums for the packages are as follows:

    b8d487298637994ccc01a4fb7d0ab76a  horde-groupware-1.0.5.tar.gz
    f39c01e029e11754f7db1a8b9bbbeccf  patch-horde-groupware-1.0.4-1.0.5.gz

Have fun!

The Horde Team.


More information about the announce mailing list