UBUNTU-CVE-2018-19205
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-19205
UBUNTU-CVE-2018-19205
Summary:
Details: Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.
References: https://ubuntu.com/security/CVE-2018-19205, https://roundcube.net/news/2018/07/27/update-1.3.7-released, https://github.com/roundcube/roundcubemail/issues/6289, https://github.com/roundcube/roundcubemail/commit/94da947855329c5062ec2a7098eb86fb675aac37, https://github.com/roundcube/roundcubemail/commit/2fa112bd836e5e144e270bda11c9fda1a66a22ae, https://github.com/roundcube/roundcubemail/releases/tag/1.3.7, https://www.cve.org/CVERecord?id=CVE-2018-19205, https://ubuntu.com/security/notices/USN-8132-1
Affected packages
Package
Name: roundcube
Purl: pkg:deb/ubuntu/[email protected]~beta+dfsg.1-0ubuntu1+esm7?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
