UBUNTU-CVE-2016-4069
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-4069
UBUNTU-CVE-2016-4069
Summary:
Details: Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.
References: https://ubuntu.com/security/CVE-2016-4069, https://github.com/roundcube/roundcubemail/issues/4957, https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115, https://github.com/roundcube/roundcubemail/commit/4a408843b0ef816daf70a472a02b78cd6073a4d5, https://github.com/roundcube/roundcubemail/commit/699af1e5206ed9114322adaa3c25c1c969640a53, http://www.openwall.com/lists/oss-security/2016/04/23/3, https://www.cve.org/CVERecord?id=CVE-2016-4069, https://ubuntu.com/security/notices/USN-8132-1
Affected packages
Package
Name: roundcube
Purl: pkg:deb/ubuntu/[email protected]~beta+dfsg.1-0ubuntu1+esm7?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
