@thomascube thomascube released this Nov 28, 2016 · 2771 commits to master since this release

Assets 8

This is a security update to the stable version 1.1. It contains one fix for a recently reported security issue when using PHP's mail() function. It has been discovered by Robin Peraglie using RIPS and more details along with a CVE number will be pulished shortly.

It's considered stable and we recommend to update all productive installations of Roundcube 1.1.x which do not have an SMTP server configured for mail delivery.

Please do backup your data before updating!


  • Fix vulnerability in handling of mail()'s 5th argument