MGASA-2015-0400
Dashboard / Vulnerabilities / MGASA-2015-0400
MGASA-2015-0400
Summary: Updated roundcubemail package fixes security vulnerabilities
Details: Multiple security issues in the DBMail driver for the password plugin, including buffer overflows (CVE-2015-2181) and the ability for a remote attacker to execute arbitrary shell commands as root (CVE-2015-2180). An authenticated user can download arbitrary files from the web server that the web server process has read access to, by uploading a vCard with a specially crafted POST (CVE-2015-5382). The roundcubemail package has been updated to version 1.0.6, fixing these issues and several other bugs, however the installer is currently known to be broken.
References: https://advisories.mageia.org/MGASA-2015-0400.html, https://bugs.mageia.org/show_bug.cgi?id=16249, https://bugs.mageia.org/show_bug.cgi?id=13056, http://openwall.com/lists/oss-security/2015/07/07/2, http://trac.roundcube.net/ticket/1490261, https://github.com/roundcube/roundcubemail/releases/tag/1.0.6, http://lists.opensuse.org/opensuse-updates/2015-06/msg00062.html
Affected packages
Package
Name: roundcubemail
Purl: pkg:rpm/mageia/roundcubemail?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
