diff --git a/CHANGELOG b/CHANGELOG index 2d7f74bd9..0239366a2 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -50,9 +50,12 @@ CHANGELOG Roundcube Webmail - Fix touch event issue on messages list in IE/Edge (#5781) - Fix so links over images are not removed in plain text signatures converted from HTML (#4473) - Fix various issues when downloading files with names containing non-ascii chars, use RFC 2231 (#5772) + +RELEASE 1.3.3 +------------- - Fix decoding of mailto: links with + character in HTML messages (#6020) - Fix false reporting of failed upgrade in installto.sh (#6019) -- Fix file disclosure vulnerability caused by insuficient input validation in relation to attachment plugins (#6026) +- Fix file disclosure vulnerability caused by insufficient input validation [CVE-2017-16651] (#6026) - Fix mangled non-ASCII characters in links in HTML messages (#6028) RELEASE 1.3.2