Horde Groupware Webmail is, zoals de naam al doet vermoeden, een pakket waarmee groupware en webmail aangeboden kan worden. Het pakket wordt geschreven in php en maakt gebruik van het Horde-framework. Voor meer informatie verwijzen we jullie door naar deze en deze pagina's. De ontwikkelaars hebben enkele dagen geleden versies 1.2.2 en 1.1.5 van Horde Groupware Webmail uitgebracht, voorzien van de volgende aankondigingen, aldus de mailinglist:
Horde Groupware Webmail Edition 1.2.2 (final)
The Horde Team is pleased to announce the final release of the Horde Groupware Webmail Edition version 1.2.2.
This is a minor security release that fixes unescaped output in the tag cloud search script, validates the Horde_Image driver name to prevent a possible local file inclusion vulnerability, and fixes unescaped output in several webmail scripts. All users are encouraged to upgrade to this release. Thanks to Gunnar Wrobel for finding these issues in a code audit.
The major changes compared to the Horde Groupware Webmail Edition version 1.2.1 are:The full list of changes (from version 1.2.1) can be viewed here.
- Fixed unescaped output in the tag cloud block.
- Fixed unvalidated Horde_Image driver name.
- Fixed unescaped output in message.php, pgp.php and smime.php.
- Fixed problems with SQL Shares and PostgreSQL.
- Added support for Mozilla Sunbird snooze properties.
- Several bugfixes and minor improvements in Mail component.
Horde Groupware Webmail Edition 1.1.5 (final)
The Horde Team is pleased to announce the final release of the Horde Groupware Webmail Edition version 1.1.5.
This is a minor security release that fixes unescaped output in the tag cloud search script, validates the Horde_Image driver name to prevent a possible local file inclusion vulnerability, and fixes unescaped output in several webmail scripts. All users are encouraged to upgrade to this release. Thanks to Gunnar Wrobel for finding these issues in a code audit.
The major changes compared to the Horde Groupware Webmail Edition version 1.1.4 are:The full list of changes (from version 1.1.4) can be viewed here.
- Fixed unescaped output in the tag cloud block.
- Fixed unvalidated Horde_Image driver name.
- Fixed unescaped output in message.php, pgp.php and smime.php.