UBUNTU-CVE-2018-19206
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-19206
UBUNTU-CVE-2018-19206
Summary:
Details: steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
References: https://ubuntu.com/security/CVE-2018-19206, https://roundcube.net/news/2018/10/26/update-1.3.8-released, https://github.com/roundcube/roundcubemail/issues/6410, https://github.com/roundcube/roundcubemail/commit/102fbf1169116fef32a940b9fb1738bc45276059, https://github.com/roundcube/roundcubemail/commit/adcac3b9de2728c34c4d2b107e54823b6a7f6a5b, https://github.com/roundcube/roundcubemail/releases/tag/1.3.8, https://www.cve.org/CVERecord?id=CVE-2018-19206, https://ubuntu.com/security/notices/USN-8132-1
Affected packages
Package
Name: roundcube
Purl: pkg:deb/ubuntu/[email protected]~beta+dfsg.1-0ubuntu1+esm7?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
