MGASA-2023-0332
Dashboard / Vulnerabilities / MGASA-2023-0332
Summary: Updated roundcubemail packages fix XSS security vulnerabilities
Details: Updated roundcubemail package fixes security vulnerabilities: Fix cross-site scripting (XSS) vulnerability in setting Content-Type/ Content-Disposition for attachment preview/download (CVE-2023-47272) Fix cross-site scripting (XSS) vulnerability in handling of SVG in HTML messages. (CVE-2023-5631) Some other errors have been fixed: - Fix PHP8 fatal error when parsing a malformed BODYSTRUCTURE - Fix duplicated Inbox folder on IMAP servers that do not use Inbox folder with all capital letters - Fix PHP warnings - Fix UI issue when dealing with an invalid managesieve_default_headers value - Fix bug where images attached to application/smil messages weren't displayed - Fix PHP string replacement error in utils/error.php - Fix regression where smtp_user did not allow pre/post strings before/after %u placeholder
References: https://advisories.mageia.org/MGASA-2023-0332.html, https://bugs.mageia.org/show_bug.cgi?id=32493, https://github.com/roundcube/roundcubemail/releases/tag/1.6.4, https://github.com/roundcube/roundcubemail/releases/tag/1.6.5
Affected packages
Package
Name: roundcubemail
Purl: pkg:rpm/mageia/roundcubemail?arch=source&distro=mageia-9
Affected ranges
Type: ECOSYSTEM
Events:
