MGASA-2016-0155
Dashboard / Vulnerabilities / MGASA-2016-0155
Summary: Updated roundcubemail packages fix security vulnerabilities
Details: Updated roundcubemail packages fix security vulnerabilities: More security issues in the DBMail driver for the password plugin, related to CVE-2015-2181. XSS issue in SVG images handling (CVE-2015-8864). Lack of protection for attachment download URLs against CSRF (CVE-2016-4069). The roundcubemail package has been updated to version 1.0.9, fixing these issues and several other bugs.
References: https://advisories.mageia.org/MGASA-2016-0155.html, https://bugs.mageia.org/show_bug.cgi?id=18257, http://openwall.com/lists/oss-security/2016/04/23/4, https://github.com/roundcube/roundcubemail/releases/tag/1.0.9, http://lists.roundcube.net/pipermail/users/2016-April/011299.html
Affected packages
Package
Name: roundcubemail
Purl: pkg:rpm/mageia/roundcubemail?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
