Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 9: Roundcube Critical XSS and Info Disclosure MGASA-2025-0332

mageia
Calendar Grey December 23, 2025
Dist Mageia Esm H88
Roundcube packages updated to fix Cross-Site Scripting and Information Disclosure issues on Mageia 9. Learn more.
MGASA-2025-0332 - Updated roundcubemail packages fix security vulnerabilities

Summary

Description: Fix Cross-Site-Scripting vulnerability via SVG's animate tag reported by Valentin T., CrowdStrike. Fix Information Disclosure vulnerability in the HTML style sanitizer reported by somerandomdev.

References

- https://bugs.mageia.org/show_bug.cgi?id=34863

- https://github.com/roundcube/roundcubemail/releases/tag/1.6.12

- https://www.cve.org/CVERecord?id=CVE-2025-68460

- https://www.cve.org/CVERecord?id=CVE-2025-68461

Resolution

SRPMS

- 9/core/roundcubemail-1.6.12-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 22 Dec 2025
URL: https://advisories.mageia.org/MGASA-2025-0332.html
Type: security
CVE: CVE-2025-68460, CVE-2025-68461

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here