The roundcubemail package has been updated to version 1.0.8, which fixes a path traversal issue and other bugs. See the upstream release announcement for more details.
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2016-0016.json"