Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian: DSA-2787-1 Critical: Roundcube Remote Access Design Error

debian
Calendar Grey October 27, 2013
Debian Logo
Enhance your roundcube instance to rectify layout issues causing remote exploit risks within Debian platforms.
It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, does not properly sanitize the _session parameter in steps/utils/save_pref.inc during sa...

Summary

roundcube in the oldstable distribution (squeeze) is not affected by
this problem.

For the stable distribution (wheezy), this problem has been fixed in
version 0.7.2-9+deb7u1.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your roundcube packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: roundcube
CVE ID: CVE-2013-6172

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here