Bug#1144059: roundcube: Multiple security vulnerabilities

Guilhem Moulin <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Source: roundcube
Version: 1.6.17+dfsg-1
Control: found -1 1.6.17+dfsg-0+deb13u1
Control: found -1 1.6.5+dfsg-1+deb12u10
Control: found -1 1.4.15+dfsg.1-1+deb11u10
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: Debian Security Team <[email protected]>

Roundcube webmail upstream has recently released 1.6.17 [0] which fixes
the following security vulnerabilities:

 1. Content proxied by the css proxy is not validated validation
    https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b
 2. SSRF bypass via specific local address URLs using 100.64.0.0/10 and
    fe80::/10 subnets
    https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223
 3. SSRF filter bypass via various forms of nip.io/sslip.io hostnames
    evading is_local_url() check
    https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9
 4. Remote content blocking bypass via unclosed url() in a FuncIRI
    attribute
    https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b
 5. LDAP filter injection via unescaped %u/%fu/%d substitution into the
    `search_filter`
    https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540
 6. Arbitrary sieve script injection via a filter rule name bypassing
    `managesieve_disabled_actions`
    https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e
 7. RCE in the `cmd_learn` driver of markasjunk plugin
    https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd
    Follow-up: https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a
 8. IMAP command injection via mail search and LITERAL+ byte-count
    desynchronization
    https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea
 9. The modoboa driver of the passwd plugin leaks an authentication
    token to a user-controlled host
    https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c
 10. Stored XSS in “Add to address book” action
     https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8
 11. HTML/CSS sanitization bypass via SVG animate `by` attribute
     https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f

(Using severity=grave due to issues #7 and #9, although they are
specific to plugins which are not enabled by default.)

AFAIK no CVE-ID have been published for these issues.  I'll request some
later today unless someone beats me to it.
-- 
Guilhem.

[0] https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmp5xGwACgkQ05pJnDwh
pVIlDA//c0czi3A6UsgRJJcOvW/eIeoVJu9IFMcGlxIb4d/7BLpMBH2sGqNCIoRO
UHDfh6PPnTokb4N2kznRDD0DlQfFtGoQzNFDJvPp8X1uMXhH0oPGLKSKVicpzrd8
O/03d/zy3NOYssV2s4z5Rh8EOFyBq6dKOUwbQwzfcX4bjfSXCqeNv/UYa07Ogf4Y
TO2MY4gYHi6juu3NxR/fgeMl57E/3FYt/Qzf8FlKz9HizzZHMOkdLqRHO+vOaGbK
X69HEoA5KFkBy1xpMfqaBjKbGIQ4kaDI2KjbeQWTxsScov2mJETX6GBZD7YlprPy
rXj7wiTjiuSRG4J9NJ8KAYn6fXm326lnEpTUOCbal5IzFWF4+TOKNPhwaGX2IU/g
qu7Et13+ZB+lWVyPxwQxzfhLWL1wpGcAYmA/SEQ59m1GUKOJ+neLhvMNXRKOk0Kh
ev7JHKKg65hXESbwjxyldqO5/w+YM+kK0Z3czi8Ecxt5KVYD9VaBOgzrzg6MbEz5
W8nsjAtDvWr/Mzb7876jnoAdZgfPe5CAK1SWKGw2vsdGmfN6G+6xza97aM1GdM33
t1+JwdQPgzO76muifHaZON/21xzqyrDl6tSZgisF+Hx99SokpXD/xDqnM+zX6dgP
EkFC3hpymKAduVnplIV+SOKfr4gtV7SEUWATD3rEMTowABJgMPg=
=yaPG
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.