- Remove personal data from Message ID seed. (#880029/847107)
- Implemented page referal verification mechanism. (Secunia Advisory SA34627)
- Implemented security token system. (Secunia Advisory SA34627)
+ - Fix issue with multi-part related messages not showing all attachments (#2830140).
+ - Fix for security token missing in newmail plugin (#2919418).
+ - Fix for mailto: urls containing + characters, thanks to Michael Puls II for the
+ patch.
+ - Make base URL autodetection more robust; fixes some lighttpd issues
+ (probably #1741469).
+ - Encoded From headers now properly quoted (#2830141).
+ - Multibyte strings (notably subjects) are now handled correctly (#2824813,
+ #2925731).
+ - X-DNS-Prefetch-Control: off header is now sent to browsers to prevent information
+ leakage when Firefox does DNS prefetching for URLs contained in emails.
+ - Added the ability to configure Google Mail (Gmail) as the mail server
+ behind SquirrelMail.
+ - Fix error with SpamCop reporting plugin not being able to send report as
+ emails (#1795310).
+ - Fix typo in SpamCop plugin.
+ - Reduced default time security tokens stay valid from 30 days to 2 days
+ (reduces chances of session data growing too large)
+ - Fixed minor vulnerability in Mail Fetch plugin [CVE-2010-1637/TEHTRI-SA-2010-009]
+ - Now properly quote personal part of encoded addresses when replying.
+ - Now fill in default subject when forwarding as attachment (#2936541).
+ - Fixed issues caused by use of PostgreSQL keyword "user" in SquirrelMail's
+ default preferences database schema (#2943483).
+ - Fixed attachment filename decoding problems (#2994865).
Version 1.5.1 (branched on 2006-02-12)
--------------------------------------