[horde] Horde Groupware Webmail Edition 1.0.6 (final)

Jan Schneider jan at horde.org
Sat Mar 8 12:54:49 UTC 2008


The Horde Team is pleased to announce the final release of the Horde Groupware
Webmail Edition version 1.0.6.

This is a security release that closes a file inclusion vulnerability through
abuse of the theme preference. All users are encouraged to upgrade to this
version.

Horde Groupware Webmail Edition is a free, enterprise ready, browser based
communication suite. Users can read, send and organize email messages and
manage and share calendars, contacts, tasks and notes with the standards
compliant components from the Horde Project.

Major changes compared to Horde Groupware Webmail Edition 1.0.5 are:
    * Fix arbitrary file inclusion through abuse of the theme preference.

The full list of changes (from version 1.0.5) can be viewed here:

http://cvs.horde.org/diff.php/groupware/docs/webmail/CHANGES?r1=1.12.2.2&r2=1.12.2.3&ty=h

The Horde Groupware Webmail Edition 1.0.6 distribution is available from the following locations:

    ftp://ftp.horde.org/pub/horde-webmail/horde-webmail-1.0.6.tar.gz
    http://ftp.horde.org/pub/horde-webmail/horde-webmail-1.0.6.tar.gz

Patches against version 1.0.5 are available at:

    ftp://ftp.horde.org/pub/horde-webmail/patches/patch-horde-webmail-1.0.5-1.0.6.gz
    http://ftp.horde.org/pub/horde-webmail/patches/patch-horde-webmail-1.0.5-1.0.6.gz

Or, for quicker access, download from your nearest mirror:

    http://www.horde.org/mirrors.php

MD5 sums for the packages are as follows:

    c0b1038a521b0df0d4587a955dff459c  horde-webmail-1.0.6.tar.gz
    b38a17a20e2461b4dd06ef461936a12b  patch-horde-webmail-1.0.5-1.0.6.gz

Have fun!

The Horde Team.


More information about the horde mailing list