[announce] [SECURITY] Horde Groupware Webmail Edition 5.2.4 (final)

Jan Schneider jan at horde.org
Wed Dec 3 16:55:29 UTC 2014


The Horde Team is pleased to announce the final release of the Horde Groupware
Webmail Edition version 5.2.4.

Horde Groupware Webmail Edition is a free, enterprise ready, browser based
communication suite. Users can read, send and organize email messages  
with four
different webmail interfaces and manage and share calendars, contacts, tasks,
notes, files, and bookmarks with the standards compliant components from the
Horde Project.

For upgrading instructions, please see
http://www.horde.org/apps/webmail/docs/UPGRADING

For detailed installation and configuration instructions, please see
http://www.horde.org/apps/webmail/docs/INSTALL

The major changes compared to the Horde Groupware Webmail Edition  
version 5.2.3
are:

General changes:
     * Small bugfixes and improvements.

Calendar changes:
     * Fixed disclosure of private events in daily agenda.
     * Fixed adding and updating events via CalDAV.
     * Fixed incomplete month views.

Notes changes:
     * Fixed permission check when editing notes. Mitigation: the  
attacker needs
       to know the note's (random) URL to exploit this flaw.
     * Small API improvement.

Thanks to Christopher Neuhaus for reporting the security issue in the note
manager.

The full list of changes can be viewed here:

https://github.com/horde/horde/blob/99921cddb7b3477a066d9ade23a724d6273de752/bundles/webmail/docs/CHANGES

Have fun!

The Horde Team.


More information about the announce mailing list