[horde] Horde Groupware Webmail Edition 1.2.1 (final)

Jan Schneider jan at horde.org
Wed Dec 10 23:51:13 UTC 2008


The Horde Team is pleased to announce the final release of the Horde Groupware
Webmail Edition version 1.2.1.

This is a minor security release that adds another check to the XSS filter for
an Internet Explorer exploit and fixes unescaped output in the test.php
scripts. All users are encouraged to upgrade to this version. In addition all
users are encouraged to disable test.php in production, per the install
documentation.

Horde Groupware Webmail Edition is a free, enterprise ready, browser based
communication suite. Users can read, send and organize email messages with
three different webmail interfaces and manage and share calendars, contacts,
tasks and notes with the standards compliant components from the Horde
Project.

The major changes compared to the Horde Groupware Webmail Edition version 1.2
are:
     * Added another check to the XSS filter (only IE is vulnerable).
     * Escape output in address book's test.php
     * Deleted attachments are now marked as 'attachment' instead of 'inline'.
     * iTip replies are sent using the regular outgoing email configuration.
     * multipart/appledouble attachments are always displayed.
     * An import script for SquirrelMail preferences and contacts.
     * Consistent access keys.
     * Fix sharing with LDAP groups.
     * Several SyncML fixes.
     * Kolab fixes for free/busy URLs and photos.
     * prototype.js has been upgraded to 1.6.0.3.
     * Fixed included Date_Holiday package.
     * Fixed configuration files upgrades.
     * Fixed database generation on PostgreSQL.

The full list of changes (from version 1.2) can be viewed here:

http://cvs.horde.org/diff.php/groupware/docs/webmail/CHANGES?r1=1.29&r2=1.35&ty=h

The Horde Groupware Webmail Edition 1.2.1 distribution is available  
from the following locations:

     ftp://ftp.horde.org/pub/horde-webmail/horde-webmail-1.2.1.tar.gz
     http://ftp.horde.org/pub/horde-webmail/horde-webmail-1.2.1.tar.gz

Patches against version 1.2 are available at:

      
ftp://ftp.horde.org/pub/horde-webmail/patches/patch-horde-webmail-1.2-1.2.1.gz
      
http://ftp.horde.org/pub/horde-webmail/patches/patch-horde-webmail-1.2-1.2.1.gz

NOTE: Patches do not contain differences between files containing binary data.
These files will need to be updated via the distribution files.

Or, for quicker access, download from your nearest mirror:

     http://www.horde.org/mirrors.php

MD5 sums for the packages are as follows:

     b08855377b370b84e49f035b296c5594  horde-webmail-1.2.1.tar.gz
     7332e93e1c0123f160a1990ec32eaf07  patch-horde-webmail-1.2-1.2.1.gz

Have fun!

The Horde Team.


More information about the horde mailing list