DavMail 6.6.0 patches a regex flaw and advances its Microsoft Graph backend (opens in new tab)
Organizations that run DavMail to bridge standard mail clients to Microsoft Exchange or Office 365 received an update this week. Version 6.6.0 addresses a code-scanning alert tied to a regex vulnerability, adjusts OAuth redirect handling to match a recent Microsoft change, and ships fixes across IMAP, SMTP, CalDAV, and CardDAV subsystems. A regex replacement closes a security alert The security change replaces a regular expression in the replaceIcal4Principal method with simple substring call...
Read the original article