Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora: Roundcube Webmail Advisory Critical: CSRF and XSS Issues

fedora
Calendar Grey May 7, 2016
Dist Fedora Esm H88
The latest Roundcube webmail security patch for Fedora 24 addresses vulnerabilities including CSRF and XSS, while also enhancing several plugin functionalities.
**Release 1.1.5** * Plugin API: Added html2text hook * Plugin API: Added addressbook_export hook * Fix missing emoticons on html-to-text conversion * Fix random "access to this ...

Summary

RoundCube Webmail is a browser-based multilingual IMAP client

with an application-like user interface. It provides full

functionality you expect from an e-mail client, including MIME

support, address book, folder manipulation, message searching

and spell checking. RoundCube Webmail is written in PHP and

requires a database: MySQL, PostgreSQL and SQLite are known to

work. The user interface is fully skinnable using XHTML and

CSS 2.

Update Information:

**Release 1.1.5** * Plugin API: Added html2text hook * Plugin API: Added addressbook_export hook * Fix missing emoticons on html-to-text conversion * Fix random "access to this resource is secured against CSRF" message at logout (#4956) * Fix missing language name in "Add to Dictionary" request in HTML mode (#4951) * Enable use of TLSv1.1 and TLSv1.2 for IMAP (#4955) * Fix XSS issue in SVG images handling (#4949) * Fix (again) security issue in DBMail driver of password plugin (CVE-2015-2181) (#4958) * Fix bug in long recipients list parsing for cases where recipient name contained @-char (#4964) * Fix additional_message_headers plugin compatibility with Mail_Mime >= 1.9 (#4966) * Hide DSN option in Preferences when smtp_server is not used (#4967) * Protect download urls against CSRF using unique request tokens (#4957) * newmail_notifier Plugin: Refactored desktop notifications * Fix so contactlist_fields option can be set via config file * ...

Read the Full Advisory

Change Log

References


[ 1 ] Bug #1330084 - CVE-2015-2181 CVE-2015-8864 CVE-2016-4068 CVE-2016-4069 roundcubemail: security issues fixed in version 1.0.9 https://bugzilla.redhat.com/show_bug.cgi?id=1330084

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update roundcubemail' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: roundcubemail
Product: Fedora 24
Version: 1.1.5
Release: 1.fc24
Summary: Round Cube Webmail is a browser-based multilingual IMAP client

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here