[announce] Horde Groupware Webmail Edition 1.0.8 (final)

Jan Schneider jan at horde.org
Wed Sep 10 11:51:27 UTC 2008


The Horde Team is pleased to announce the final release of the Horde Groupware
Webmail Edition version 1.0.8.

This is a security release that further improves the XSS filter for HTML
messages (CVE-2008-3824). All users are encouraged to upgrade to this version.

Many thanks to Alexios Fakos for detecting this vulnerability, and oCERT for
notifying us.

Horde Groupware Webmail Edition is a free, enterprise ready, browser based
communication suite. Users can read, send and organize email messages and
manage and share calendars, contacts, tasks and notes with the standards
compliant components from the Horde Project.

Major changes compared to Horde Groupware Webmail Edition 1.0.7 are:
     * Further improved the XSS filter for HTML.

The full list of changes (from version 1.0.7) can be viewed here:

http://cvs.horde.org/diff.php/groupware/docs/webmail/CHANGES?r1=1.12.2.4&r2=1.12.2.6&ty=h

The Horde Groupware Webmail Edition 1.0.8 distribution is available  
from the following locations:

     ftp://ftp.horde.org/pub/horde-webmail/horde-webmail-1.0.8.tar.gz
     http://ftp.horde.org/pub/horde-webmail/horde-webmail-1.0.8.tar.gz

Patches against version 1.0.7 are available at:

      
ftp://ftp.horde.org/pub/horde-webmail/patches/patch-horde-webmail-1.0.7-1.0.8.gz
      
http://ftp.horde.org/pub/horde-webmail/patches/patch-horde-webmail-1.0.7-1.0.8.gz

NOTE: Patches do not contain differences between files containing binary data.
These files will need to be updated via the distribution files.

Or, for quicker access, download from your nearest mirror:

     http://www.horde.org/mirrors.php

MD5 sums for the packages are as follows:

     0cf9a87217d1698be7fa72504cf9292f  horde-webmail-1.0.8.tar.gz
     ca3a36cb54f04d3954a53ed14cda87dc  patch-horde-webmail-1.0.7-1.0.8.gz

Have fun!

The Horde Team.


More information about the announce mailing list