FS#47764 - [roundcubemail] CVE-2015-8770: remote code execution
Attached to Project:
Community Packages
Opened by Remi Gacogne (rgacogne) - Friday, 15 January 2016, 08:31 GMT
Last edited by Sergej Pupykin (sergej) - Friday, 15 January 2016, 16:28 GMT
Opened by Remi Gacogne (rgacogne) - Friday, 15 January 2016, 08:31 GMT
Last edited by Sergej Pupykin (sergej) - Friday, 15 January 2016, 16:28 GMT
|
Details
Hi,
roundcubemail recently fixed a vulnerability in the 1.1.4 and 1.0.8 releases [1], initially disclosed as a "potential path traversal" but in fact leading to remote code execution [2]. I believe we should apply as soon as possible the fix that has been committed to the master trunk [3], as there has been no release for the 1.2 (beta) branch we are shipping. [1]: https://roundcube.net/news/2015/12/26/updates-1.1.4-and-1.0.8-released/ [2]: http://seclists.org/bugtraq/2016/Jan/60 [3]: https://github.com/roundcube/roundcubemail/commit/10e5192a2b1bc90ec137f5e69d0aa072c1210d6d |
This task depends upon