Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE 2024:0328-1 moderate: roundcubemail XSS and info leak fix

opensuse
Calendar Grey October 9, 2024
Dist Opensuse Esm H88
openSUSE has published a critical Security Patch for roundcubemail, addressing various vulnerabilities and XSS weaknesses within the software.
An update that fixes three vulnerabilities is now available

Description

This update for roundcubemail fixes the following issues:

Update to 1.6.8 This is a security update to the stable version 1.6 of

Roundcube Webmail. It provides fixes to recently reported security

vulnerabilities:

* Fix XSS vulnerability in post-processing of sanitized HTML content

[CVE-2024-42009]

* Fix XSS vulnerability in serving of attachments other than HTML or SVG

[CVE-2024-42008]

* Fix information leak (access to remote content) via insufficient CSS

filtering [CVE-2024-42010]

CHANGELOG

* Managesieve: Protect special scripts in managesieve_kolab_master mode

* Fix newmail_notifier notification focus in Chrome (#9467)

* Fix fatal error when parsing some TNEF attachments (#9462)

* Fix double scrollbar when composing a mail with many plain text lines

(#7760)

* Fix decoding mail parts with multiple base64-encoded text blocks

(#9290)

* Fix bug where some messages could get malformed in...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2024-328=1

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2024-328=1

Package List

- openSUSE Backports SLE-15-SP6 (noarch):

roundcubemail-1.6.8-bp156.2.3.1

- openSUSE Backports SLE-15-SP5 (noarch):

roundcubemail-1.6.8-bp155.2.12.1

References

https://www.suse.com/security/cve/CVE-2024-42008.html

https://www.suse.com/security/cve/CVE-2024-42009.html

https://www.suse.com/security/cve/CVE-2024-42010.html

https://bugzilla.suse.com/1228900

https://bugzilla.suse.com/1228901

Announcement ID: openSUSE-SU-2024:0328-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP5 openSUSE Backports SLE-15-SP6 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here