Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 29: FEDORA-2018-e3a5e37c5e Critical: Nextcloud SQL Injection Issue

fedora
Calendar Grey April 27, 2018
Dist Fedora Esm H88
The latest release of Roundcubemail 1.3.6 resolves a critical command injection vulnerability and enhances its interoperability with PHP version 7.2.
Upstream announcement: **Version 1.3.6** This is a security update to the stable version 1.3

Summary

RoundCube Webmail is a browser-based multilingual IMAP client

with an application-like user interface. It provides full

functionality you expect from an e-mail client, including MIME

support, address book, folder manipulation, message searching

and spell checking. RoundCube Webmail is written in PHP and

requires a database: MySQL, PostgreSQL and SQLite are known to

work. The user interface is fully skinnable using XHTML and

CSS 2.

Upstream announcement: **Version 1.3.6** This is a security update to the

stable version 1.3. It primarily fixes a recently discovered IMAP command

injection vulnerability caused by insufficient input validation within the

archive plugin. Details about the vulnerability are published under

CVE-2018-9846. Additionally, we back-ported some minor fixes from the master

branch which improve PHP 7.2 compatibility as well as PGP signing and key

handling for those who use the Enigma plugin. See the complete changelog below.

We strongly recommend to update all productive installations of Roundcube.

Please do backup your data before updating! **CHANGELOG** * Fix parsing

date strings (e.g. from a Date: mail header) with comments (#6216) * Fix PHP

7.2: count(): Parameter must be an array in enchant-based spellchecker (#6234) *

Fix possible IMAP command injection and type juggling vulnerabilities (#6229) *

Enigma: Fix key selection for signing * Enigma: Enable keypair generation on

Internet Explorer 11 * Fix check_request() bypass in places using get_uids()

[CVE-2018-9846] (#6238) * Fix bug where usernames without domain part could

be malformed or converted to lower-case on logon (#6224)

* Thu Apr 12 2018 Remi Collet - 1.3.6-1

- Update to 1.3.6

su -c 'dnf upgrade --advisory FEDORA-2018-c279b3696f' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 1.3.6
Release: 1.fc28
Summary: Round Cube Webmail is a browser-based multilingual IMAP client

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here