Bug#1144059: roundcube: Multiple security vulnerabilities
Guilhem Moulin <[email protected]>
| Newsgroups | gmane.linux.debian.devel.bugs.rc |
|---|---|
| Message-ID | <[email protected]> |
Source: roundcube Version: 1.6.17+dfsg-1 Control: found -1 1.6.17+dfsg-0+deb13u1 Control: found -1 1.6.5+dfsg-1+deb12u10 Control: found -1 1.4.15+dfsg.1-1+deb11u10 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: Debian Security Team <[email protected]> Roundcube webmail upstream has recently released 1.6.17 [0] which fixes the following security vulnerabilities: 1. Content proxied by the css proxy is not validated validation https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b 2. SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 subnets https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223 3. SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9 4. Remote content blocking bypass via unclosed url() in a FuncIRI attribute https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b 5. LDAP filter injection via unescaped %u/%fu/%d substitution into the `search_filter` https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540 6. Arbitrary sieve script injection via a filter rule name bypassing `managesieve_disabled_actions` https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e 7. RCE in the `cmd_learn` driver of markasjunk plugin https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd Follow-up: https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a 8. IMAP command injection via mail search and LITERAL+ byte-count desynchronization https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea 9. The modoboa driver of the passwd plugin leaks an authentication token to a user-controlled host https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c 10. Stored XSS in “Add to address book” action https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8 11. HTML/CSS sanitization bypass via SVG animate `by` attribute https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f (Using severity=grave due to issues #7 and #9, although they are specific to plugins which are not enabled by default.) AFAIK no CVE-ID have been published for these issues. I'll request some later today unless someone beats me to it. -- Guilhem. [0] https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmp5xGwACgkQ05pJnDwh pVIlDA//c0czi3A6UsgRJJcOvW/eIeoVJu9IFMcGlxIb4d/7BLpMBH2sGqNCIoRO UHDfh6PPnTokb4N2kznRDD0DlQfFtGoQzNFDJvPp8X1uMXhH0oPGLKSKVicpzrd8 O/03d/zy3NOYssV2s4z5Rh8EOFyBq6dKOUwbQwzfcX4bjfSXCqeNv/UYa07Ogf4Y TO2MY4gYHi6juu3NxR/fgeMl57E/3FYt/Qzf8FlKz9HizzZHMOkdLqRHO+vOaGbK X69HEoA5KFkBy1xpMfqaBjKbGIQ4kaDI2KjbeQWTxsScov2mJETX6GBZD7YlprPy rXj7wiTjiuSRG4J9NJ8KAYn6fXm326lnEpTUOCbal5IzFWF4+TOKNPhwaGX2IU/g qu7Et13+ZB+lWVyPxwQxzfhLWL1wpGcAYmA/SEQ59m1GUKOJ+neLhvMNXRKOk0Kh ev7JHKKg65hXESbwjxyldqO5/w+YM+kK0Z3czi8Ecxt5KVYD9VaBOgzrzg6MbEz5 W8nsjAtDvWr/Mzb7876jnoAdZgfPe5CAK1SWKGw2vsdGmfN6G+6xza97aM1GdM33 t1+JwdQPgzO76muifHaZON/21xzqyrDl6tSZgisF+Hx99SokpXD/xDqnM+zX6dgP EkFC3hpymKAduVnplIV+SOKfr4gtV7SEUWATD3rEMTowABJgMPg= =yaPG -----END PGP SIGNATURE-----