This update fixes cross-site scripting (XSS) via HTML messages with malicious CSS content (CVE-2021-26925). References: - https://bugs.mageia.org/show_bug.cgi?id=28387 . MGASA-2021-0130 - Updated roundcubemail package fixes security vulnerability Publication date: 12 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0130.html Type: security Affected Mageia releases: 7 CVE: CVE-2021-26925 This update fixes cross-site scripting (XSS) via HTML messages with malicious CSS content (CVE-2021-26925). References: - https://bugs.mageia.org/show_bug.cgi?id=28387 - https://roundcube.net/news/2021/02/08/security-update-1.4.11 - https://www.cve.org/CVERecord?id=CVE-2021-26925 SRPMS: - 7/core/roundcubemail-1.4.11-1.mga7 . Mageia 2021-0130 addresses a vulnerability in roundcubemail, improving defenses against cross-site scripting and bolstering overall system integrity.. roundcubemail update,cross-site scripting fix,mageia security update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.