UBUNTU-CVE-2017-16651

    Dashboard / Vulnerabilities / UBUNTU-CVE-2017-16651

    UBUNTU-CVE-2017-16651

    Published: 9 Nov 2017Last Modified: 4 Feb 2026
    Upstream:
    Aliases:

    Summary:

    Details: Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

    Affected packages

    Package

    Name: roundcube

    Purl: pkg:deb/ubuntu/[email protected]~beta+dfsg.1-0ubuntu1+esm5?arch=source&distro=esm-apps/xenial

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.2~beta+dfsg.1-0ubuntu1+esm5

    Affected versions

    1.1.1+dfsg.1-2
    1.1.2+dfsg.1-5
    1.1.3+dfsg.1-1
    1.1.4+dfsg.1-1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    UBUNTU-CVE-2017-16651 | CVE-DB