Updated roundcubemail package fixes security vulnerability:
This update fixes a recently discovered IMAP command injection vulnerability caused by insufficient input validation within the archive plugin. (CVE-2018-9846).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2018-0288.json"