ALT-BU-2018-3263-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2018-1000071
roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.
Modified: 2024-11-21
CVE-2018-9846
In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after a %0d%0a sequence. NOTE: this is less easily exploitable in 1.3.4 and later because of a Same Origin Policy protection mechanism.
- https://github.com/roundcube/roundcubemail/issues/6229
- https://github.com/roundcube/roundcubemail/issues/6229
- https://github.com/roundcube/roundcubemail/issues/6238
- https://github.com/roundcube/roundcubemail/issues/6238
- https://medium.com/%40ndrbasi/cve-2018-9846-roundcube-303097048b0a
- https://medium.com/%40ndrbasi/cve-2018-9846-roundcube-303097048b0a
- DSA-4181
- DSA-4181
Package alterator-l10n updated to version 2.9.40-alt1 for branch sisyphus in task 206511.
Closed bugs
«Вернуть» на «Отменить»