Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian DSA-5714-1 Moderate: Roundcube XSS Risk Addressed

debian
Calendar Grey June 18, 2024
Debian Logo
Roundcube addresses XSS flaws in Debian, boosting security measures and advising system upgrades.
Huy Nguyễn Phạm Nhật, and Valentin T

Summary

Huy Nguyễn Phạm Nhật, and Valentin T. and Lutz Wolf of CrowdStrike,
discovered that roundcube, a skinnable AJAX based webmail solution for
IMAP servers, did not correctly process and sanitize requests. This
would allow an attacker to perform Cross-Side Scripting (XSS) attacks.

For the oldstable distribution (bullseye), these problems have been fixed
in version 1.4.15+dfsg.1-1+deb11u3.

For the stable distribution (bookworm), these problems have been fixed in
version 1.6.5+dfsg-1+deb12u2.

We recommend that you upgrade your roundcube packages.

For the detailed security status of roundcube please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/roundcube

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: roundcube
CVE ID: CVE-2024-37383 CVE-2024-37384

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here