Chuck Hagenbuch | 8 Mar 2008 00:05
Favicon
Gravatar

Horde 3.1.7 (final)

The Horde Team is pleased to announce the final release of the Horde
Application Framework version 3.1.7.

This is a security release that closes a file inclusion vulnerability
through abuse of the theme preference.

The Horde Application Framework is a modular, general-purpose web application
framework written in PHP. It provides an extensive array of libraries that are
targeted at the common problems and tasks involved in developing modern web
applications.

Major changes compared to Horde 3.1.6 are:
    * Fix arbitrary file inclusion through abuse of the theme preference.

The full list of changes (from version 3.1.6) can be viewed here:

http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.312.2.2&r2=1.515.2.312.2.5&ty=h

The Horde 3.1.7 distribution is available from the following locations:

    ftp://ftp.horde.org/pub/horde/horde-3.1.7.tar.gz
    http://ftp.horde.org/pub/horde/horde-3.1.7.tar.gz

Patches against version 3.1.6 are available at:

    ftp://ftp.horde.org/pub/horde/patches/patch-horde-3.1.6-3.1.7.gz
    http://ftp.horde.org/pub/horde/patches/patch-horde-3.1.6-3.1.7.gz

Or, for quicker access, download from your nearest mirror:

(Continue reading)

Jan Schneider | 8 Mar 2008 13:36
Favicon
Gravatar

Horde Groupware 1.0.5 (final)

The Horde Team is pleased to announce the final release of the Horde Groupware
version 1.0.5.

This is a security release that closes a file inclusion vulnerability through
abuse of the theme preference. All users are encouraged to upgrade to this
version.

Horde Groupware is a free, enterprise ready, browser based collaboration
suite. Users can manage and share calendars, contacts, tasks and notes with the
standards compliant components from the Horde Project.

Major changes compared to Horde Groupware 1.0.4 are:
    * Fix arbitrary file inclusion through abuse of the theme preference.

The full list of changes (from version 1.0.4) can be viewed here:

http://cvs.horde.org/diff.php/groupware/docs/groupware/CHANGES?r1=1.17.2.2&r2=1.17.2.3&ty=h

The Horde Groupware 1.0.5 distribution is available from the following locations:

    ftp://ftp.horde.org/pub/horde-groupware/horde-groupware-1.0.5.tar.gz
    http://ftp.horde.org/pub/horde-groupware/horde-groupware-1.0.5.tar.gz

Patches against version 1.0.4 are available at:

    ftp://ftp.horde.org/pub/horde-groupware/patches/patch-horde-groupware-1.0.4-1.0.5.gz
    http://ftp.horde.org/pub/horde-groupware/patches/patch-horde-groupware-1.0.4-1.0.5.gz

Or, for quicker access, download from your nearest mirror:

(Continue reading)

Jan Schneider | 8 Mar 2008 13:54
Favicon
Gravatar

Horde Groupware Webmail Edition 1.0.6 (final)

The Horde Team is pleased to announce the final release of the Horde Groupware
Webmail Edition version 1.0.6.

This is a security release that closes a file inclusion vulnerability through
abuse of the theme preference. All users are encouraged to upgrade to this
version.

Horde Groupware Webmail Edition is a free, enterprise ready, browser based
communication suite. Users can read, send and organize email messages and
manage and share calendars, contacts, tasks and notes with the standards
compliant components from the Horde Project.

Major changes compared to Horde Groupware Webmail Edition 1.0.5 are:
    * Fix arbitrary file inclusion through abuse of the theme preference.

The full list of changes (from version 1.0.5) can be viewed here:

http://cvs.horde.org/diff.php/groupware/docs/webmail/CHANGES?r1=1.12.2.2&r2=1.12.2.3&ty=h

The Horde Groupware Webmail Edition 1.0.6 distribution is available from the following locations:

    ftp://ftp.horde.org/pub/horde-webmail/horde-webmail-1.0.6.tar.gz
    http://ftp.horde.org/pub/horde-webmail/horde-webmail-1.0.6.tar.gz

Patches against version 1.0.5 are available at:

    ftp://ftp.horde.org/pub/horde-webmail/patches/patch-horde-webmail-1.0.5-1.0.6.gz
    http://ftp.horde.org/pub/horde-webmail/patches/patch-horde-webmail-1.0.5-1.0.6.gz

Or, for quicker access, download from your nearest mirror:
(Continue reading)

Chuck Hagenbuch | 13 Mar 2008 05:43
Favicon
Gravatar

Horde 3.2-RC3

The Horde Team is pleased to announce the third release candidate of the Horde
Application Framework version 3.2.

The Horde Application Framework is a modular, general-purpose web application
framework written in PHP.  It provides an extensive array of classes that are
targeted at the common problems and tasks involved in developing modern web
applications.

Barring any problems, this code will be released as Horde 3.2.
Testing is requested and comments are encouraged.
Updated translations would also be great.

The major changes compared to the Horde version H3 (3.2-RC2) are:
    * Fixed Horde_Compress_zip::checkZipData.
    * Allow adding attachments to the problem reporting form.
    * An experimental native SQL Share driver.
    * A mock Groups driver for sites that don't need Groups.
    * The Browser class recognizes IE8
    * CSRF-protection tokens added to log out links.
    * Several multibyte string functions have been improved.
    * Many further bugfixes and improvements.

The full list of changes (from version 3.2-RC2) can be viewed here:

http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.331&r2=1.515.2.360&ty=h

The Horde 3.2-RC3 distribution is available from the following locations:

    ftp://ftp.horde.org/pub/horde/horde-3.2-rc3.tar.gz
    http://ftp.horde.org/pub/horde/horde-3.2-rc3.tar.gz
(Continue reading)

Chuck Hagenbuch | 13 Mar 2008 05:51
Favicon
Gravatar

IMP H3 (4.2-RC3)

The Horde Team is pleased to announce the second release candidate of the IMP
Webmail Client version H3 (4.2).

IMP, the Internet Messaging Program, is one of the most popular webmail
applications available.  It allows universal, web-based access to IMAP and
POP3 mail servers and provides a full range of features normally found only in
desktop email clients.

Barring any problems, this code will be released as IMP H3 (4.2).
Testing is requested and comments are encouraged.
Updated translations would also be great.

The major changes compared to the IMP version H3 (4.2-RC2) are:
    * Protect mailbox, message, and folder actions with CSRF tokens.
    * Fixed showing suggestions for the second or subsequent misspelled word.
    * Added a configuration option to force users to IMP, DIMP, or MIMP.
    * Localized default folder names.
    * %l and %d are replaced with the current short username and domain name in spam
      reporting shell calls.
    * Added a hook-based quota driver.
    * Made xinha add BR tag instead of P tag on enter keypress (Mozilla only).
    * Added fckeditor to the list of supported javascript editors.
    * Filter HTML body when replying to HTML messages with the WYIWYG editor.
    * Allow users to set the HTML editor toolbar buttons in their preferences.
    * Fixed charset of composed HTML messages.
    * Fixed message action dropdowns in IE.
    * Fixed improper enabling of HTML composition on replies.
    * Fixed popup URL generation.
    * Further bugfixes and improvements.

(Continue reading)

Chuck Hagenbuch | 13 Mar 2008 05:54
Favicon
Gravatar

DIMP H3 (1.0-RC3)

The Horde Team is pleased to announce the third release candidate of the
Dynamic Internet Messaging Program (DIMP) version H3 (1.0).

DIMP (Dynamic Internet Messaging Program, or Dynamic IMP) is a PHP-based
webmail system and a component of the Horde project.  DIMP is a version of the
webmail client IMP utilizing AJAX-like technologies to allow a more dynamic
user experience than traditionally offered via IMP.

Barring any problems, this code will be released as DIMP H3 (1.0).
Testing is requested and comments are encouraged.
Updated translations would also be great.

The major changes compared to the DIMP version H3 (1.0-RC2) are:
    * Compatiblity with IMP H3 (4.2-RC3+).
    * Use IMP's configuration for javascript editors and CSS/JS caching.
    * Made fckeditor add BR tag instead of P tag on enter keypress.
    * Made xinha add BR tag instead of P tag on enter keypress (Mozilla only).
    * Added Special Characters to compose screen, if configured.
    * Allow users to set the HTML editor toolbar buttons in their preferences.
    * Added Spanish translation.
    * Added "Reply to List" option.
    * Added Russian translation.
    * Added Hungarian translation.
    * Further bugfixes and improvements.

DIMP requires Horde version 3.2 and IMP version H3 (4.2 RC3+) to run.

The full list of changes (from version H3 (1.0-RC2)) can be viewed here:

http://cvs.horde.org/diff.php/dimp/docs/CHANGES?r1=1.69.2.4&r2=1.69.2.12&ty=h
(Continue reading)

Chuck Hagenbuch | 13 Mar 2008 05:56
Favicon
Gravatar

MIMP H3 (1.1-RC2)

The Horde Team is pleased to announce the second release candidate of the MIMP
Webmail Client version H3 (1.1).

MIMP (Mobile Internet Messaging Program, or Mobile IMP) is a version of the
webmail client IMP suitable for mobile devices such as WAP phones or
PDAs. Basic IMP functionality is implemented including mailbox viewing and
paging, viewing messages, deleting, replying, forwarding, and composing new
messages.

This is a preview version that should not be used on production systems.  This
version is considered feature complete but there might still be a few bugs.
You should not use this preview version over existing production data.

We encourage widespread testing and feedback via the mailing lists or our bug
tracking system.  Updated translations are very welcome, though some strings
might still change before the final release.

The major changes compared to the MIMP version H3 (1.1-RC1) are:
    * Compatiblity with the latest IMP 4.2-RC3.
    * Further bugfixes and improvements.

MIMP H3 (1.1) requires Horde version 3.2 and IMP version H3 (4.2-RC3+) to run.

The full list of changes (from version H3 (1.1-RC1)) can be viewed here:

http://cvs.horde.org/diff.php/mimp/docs/CHANGES?r1=1.59&r2=1.46.2.15&ty=h

The MIMP H3 (1.1-RC2) distribution is available from the following locations:

    ftp://ftp.horde.org/pub/mimp/mimp-h3-1.1-rc2.tar.gz
(Continue reading)

Jan Schneider | 13 Mar 2008 16:16
Favicon
Gravatar

Horde Groupware Webmail Edition 1.1-RC3

The Horde Team is pleased to announce the third release candidate of the Horde
Groupware Webmail Edition version 1.1.

Horde Groupware Webmail Edition is a free, enterprise ready, browser based
communication suite. Users can read, send and organize email messages and
manage and share calendars, contacts, tasks and notes with the standards
compliant components from the Horde Project.

Barring any problems, this code will be released as Horde Groupware Webmail
Edition 1.1.
Testing is requested and comments are encouraged.
Updated translations would also be great.

The major changes compared to the Horde Groupware Webmail Edition version
1.1-RC2 are:
    * Added a configuration option to force users to one of the webmail
      frontends.
    * Localized default folder names.
    * Allow adding attachments to the problem reporting form.
    * An experimental native SQL Share driver.
    * A mock Groups driver for sites that don't need Groups.
    * The Browser class recognizes IE8
    * CSRF-protection tokens added to log out links and mailbox, message, and
      folder actions.
    * %l and %d are replaced with the current short username and domain name
      in spam reporting shell calls.
    * Added a hook-based quota driver.
    * Made xinha add BR tag instead of P tag on enter keypress (Mozilla only).
    * Added fckeditor to the list of supported javascript editors.
    * Filter HTML body when replying to HTML messages with the WYIWYG editor.
(Continue reading)


Gmane