Roundcube Webmail allows arbitrary password resets by authenticated users. The issue is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin. . Hash: SHA512 Package : roundcube Version : 0.7.2-9+deb7u7 CVE ID : CVE-2017-8114 Debian Bug : 861388 Roundcube Webmail allows arbitrary password resets by authenticated users. The issue is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin. For Debian 7 "Wheezy", these problems have been fixed in version 0.7.2-9+deb7u7. We recommend that you upgrade your roundcube packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Roundcube Webmail application supports the functionality of user password resets. A corrective update is accessible in Debian 7 through version 0.7.2-9+deb7u7.. Roundcube Security, Debian Update, Webmail Fix, User Authentication Patch. . LinuxSecurity.com Team
Several vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2975-1
Get the latest Linux and open source security news straight to your inbox.