ALT-PU-2022-3493-1
Package roundcube updated to version 1.5.1-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Published: 2021-09-13
BDU:2021-06259
Уязвимость почтового клиента Roundcube, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнить произвольный SQL-код
Severity: CRITICAL (9.8)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2021-11-19
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-44025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
Severity: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References:
- https://bugs.debian.org/1000156
- https://bugs.debian.org/1000156
- https://github.com/roundcube/roundcubemail/commit/7d7b1dfeff795390b69905ceb63d6391b5b0dfe7
- https://github.com/roundcube/roundcubemail/commit/7d7b1dfeff795390b69905ceb63d6391b5b0dfe7
- https://github.com/roundcube/roundcubemail/commit/faf99bf8a2b7b7562206fa047e8de652861e624a
- https://github.com/roundcube/roundcubemail/commit/faf99bf8a2b7b7562206fa047e8de652861e624a
- https://github.com/roundcube/roundcubemail/issues/8193
- https://github.com/roundcube/roundcubemail/issues/8193
- [debian-lts-announce] 20211206 [SECURITY] [DLA 2840-1] roundcube security update
- [debian-lts-announce] 20211206 [SECURITY] [DLA 2840-1] roundcube security update
- FEDORA-2021-43d3c10590
- FEDORA-2021-43d3c10590
- FEDORA-2021-167865df98
- FEDORA-2021-167865df98
- DSA-5013
- DSA-5013
Published: 2021-11-19
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-44026
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- https://bugs.debian.org/1000156
- https://bugs.debian.org/1000156
- https://github.com/roundcube/roundcubemail/commit/c8947ecb762d9e89c2091bda28d49002817263f1
- https://github.com/roundcube/roundcubemail/commit/c8947ecb762d9e89c2091bda28d49002817263f1
- https://github.com/roundcube/roundcubemail/commit/ee809bde2dcaa04857a919397808a7296681dcfa
- https://github.com/roundcube/roundcubemail/commit/ee809bde2dcaa04857a919397808a7296681dcfa
- [debian-lts-announce] 20211206 [SECURITY] [DLA 2840-1] roundcube security update
- [debian-lts-announce] 20211206 [SECURITY] [DLA 2840-1] roundcube security update
- FEDORA-2021-43d3c10590
- FEDORA-2021-43d3c10590
- FEDORA-2021-167865df98
- FEDORA-2021-167865df98
- DSA-5013
- DSA-5013