Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 41: 2025-a5f56fe8ff critical: roundcubemail RCE issue

fedora
Calendar Grey June 11, 2025
Dist Fedora Esm H88
Latest security patch for Roundcube Webmail on Fedora improves reliability and mitigates RCE vulnerabilities. Update is advised.
This is a security update to the stable version 1.6 of Roundcube Webmail

Summary

RoundCube Webmail is a browser-based multilingual IMAP client

with an application-like user interface. It provides full

functionality you expect from an e-mail client, including MIME

support, address book, folder manipulation, message searching

and spell checking. RoundCube Webmail is written in PHP and

requires a database: MySQL, PostgreSQL and SQLite are known to

work. The user interface is fully skinnable using XHTML and

CSS 2.

Update Information:

This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities: Fix Post-Auth RCE via PHP Object Deserialization reported by firs0v. This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating! CHANGELOG Managesieve: Fix match-type selector (remove unsupported options) in delete header action (#9610) Improve installer to fix confusion about disabling SMTP authentication (#9801) Fix PHP warning in index.php (#9813) OAuth: Fix/improve token refresh Fix dark mode bug where wrong colors were used for blockquotes in HTML mail preview (#9820) Fix HTML message preview if it contains floating tables (#9804) Fix removing/expiring redis/memcache records when using a key prefix Fix bug where a wrong SPECIAL-USE folder could have been detected, if there were more than one per-type (#9781) Fix a default v...

Change Log

* Mon Jun 2 2025 Remi Collet - 1.6.11-1 - update to 1.6.11

References


[ 1 ] Bug #2369708 - CVE-2025-49113 roundcubemail: From CVEorg collector [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2369708

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a5f56fe8ff' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: roundcubemail
Product: Fedora 41
Version: 1.6.11
Release: 1.fc41
Summary: Round Cube Webmail is a browser-based multilingual IMAP client

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here